In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.
https://jorani.org/security-features-in-lms.html
https://github.com/Orange-Cyberdefense/CVE-repository/tree/master
http://packetstormsecurity.com/files/174248/Jorani-Remote-Code-Execution.html