Command injection in `/main/webservices/additional_webservices.php`
in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain
remote code execution via improper neutralisation of special characters.
id: CVE-2023-3368
info:
name: Chamilo LMS <= v1.11.20 Unauthenticated Command Injection
author:
...