CVE-2013-6787: Chamilo Lms

Medium severity, CVSS 6.0. EPSS: 2.7% chance of exploitation in the next 30 days.

SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlier, when using the non-encrypted passwords mode set at installation, allows remote authenticated users to execute arbitrary SQL commands via the "password0" parameter.

Affected products

  • Chamilo Chamilo Lms: up to and including 1.9.6; version 1.8.6.2 only; version 1.8.7 only; version 1.8.7.1 only; version 1.8.8.2 only; version 1.8.8.4 only; …

Published 2013-12-05. Last modified 2026-06-17.