main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-34187.json"