CVE-2023-3368: Chamilo LMS Unauthenticated Command Injection
Command injection in /main/webservices/additionalwebservices.php in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-3368?
CVE-2023-3368 is a vulnerability in Chamilo LMS that allows unauthenticated attackers to obtain remote code execution via command injection.
What is the severity of CVE-2023-3368?
The severity of CVE-2023-3368 is critical with a CVSS score of 9.8.
How does CVE-2023-3368 work?
CVE-2023-3368 works by exploiting improper neutralization of special characters in the '/main/webservices/additional_webservices.php' file in Chamilo LMS version <= v1.11.20, allowing unauthenticated attackers to execute remote code.
How can I fix CVE-2023-3368?
To fix CVE-2023-3368, you should update Chamilo LMS to a version higher than v1.11.20.
Where can I find more information about CVE-2023-3368?
For more information about CVE-2023-3368, you can refer to the following links: [1] [2] [3]