First published: Tue Nov 28 2023(Updated: )
Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960.
Credit: info@starlabs.sg
Affected Software | Affected Version | How to fix |
---|---|---|
Chamilo Chamilo | <1.11.20 |
https://https://github.com/chamilo/chamilo-lms/commit/4c69b294f927db62092e01b70ac9bd6e32d5b48b
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3368 is a vulnerability in Chamilo LMS that allows unauthenticated attackers to obtain remote code execution via command injection.
The severity of CVE-2023-3368 is critical with a CVSS score of 9.8.
CVE-2023-3368 works by exploiting improper neutralization of special characters in the '/main/webservices/additional_webservices.php' file in Chamilo LMS version <= v1.11.20, allowing unauthenticated attackers to execute remote code.
To fix CVE-2023-3368, you should update Chamilo LMS to a version higher than v1.11.20.
For more information about CVE-2023-3368, you can refer to the following links: [1] [2] [3]