First published: Thu Sep 29 2022(Updated: )
A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Chamilo Chamilo | =1.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40407 is a zip slip vulnerability in the file upload function of Chamilo v1.11 that allows attackers to execute arbitrary code via a crafted Zip file.
CVE-2022-40407 has a severity rating of 8.8 (high).
CVE-2022-40407 affects Chamilo v1.11 by allowing attackers to execute arbitrary code through a specially crafted Zip file uploaded via the file upload function.
Yes, a fix for CVE-2022-40407 is available. It is recommended to update Chamilo v1.11 to the latest version to mitigate the vulnerability.
You can find more information about CVE-2022-40407 at the following references: [GitHub](https://github.com/alexmackey/security-research/blob/main/chamilo/ChamiloRceViaZipSlip.md), [GitHub](https://github.com/chamilo/chamilo-lms), [Chamilo Support](https://support.chamilo.org/projects/chamilo-18/wiki/Security_issues#Issue-94-2022-09-06-High-impact-Moderate-risk-Authenticated-RCE-via-zipslip-attack-in-file-upload).