CVE-2022-40407: Malicious File Upload
A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-40407?
CVE-2022-40407 is a zip slip vulnerability in the file upload function of Chamilo v1.11 that allows attackers to execute arbitrary code via a crafted Zip file.
What is the severity of CVE-2022-40407?
CVE-2022-40407 has a severity rating of 8.8 (high).
How does CVE-2022-40407 affect Chamilo v1.11?
CVE-2022-40407 affects Chamilo v1.11 by allowing attackers to execute arbitrary code through a specially crafted Zip file uploaded via the file upload function.
Is there a fix for CVE-2022-40407?
Yes, a fix for CVE-2022-40407 is available. It is recommended to update Chamilo v1.11 to the latest version to mitigate the vulnerability.
Where can I find more information about CVE-2022-40407?
You can find more information about CVE-2022-40407 at the following references: [GitHub](https://github.com/alexmackey/security-research/blob/main/chamilo/ChamiloRceViaZipSlip.md), [GitHub](https://github.com/chamilo/chamilo-lms), [Chamilo Support](https://support.chamilo.org/projects/chamilo-18/wiki/Security_issues#Issue-94-2022-09-06-High-impact-Moderate-risk-Authenticated-RCE-via-zipslip-attack-in-file-upload).