CVE-2023-34944: Malicious File Upload
Published Jun 13, 2023
·Updated
An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11. up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file.
Affected Software
1 affected component
Chamilo Chamilo LMS>=1.11.0<=1.11.18
Remediation
Event History
Jun 13, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-34944?
CVE-2023-34944 is an arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 that allows attackers to execute arbitrary code via uploading a crafted SVG file.
2
How severe is CVE-2023-34944?
CVE-2023-34944 has a severity rating of 9.8 (critical).
3
Which software versions are affected by CVE-2023-34944?
Chamilo 1.11.* up to v1.11.18 is affected by CVE-2023-34944.
4
How can an attacker exploit CVE-2023-34944?
An attacker can exploit CVE-2023-34944 by uploading a crafted SVG file via the /fileUpload.lib.php component.
5
Is there a fix for CVE-2023-34944?
Yes, a fix for CVE-2023-34944 is available. Make sure to update Chamilo to version 1.11.19 or later.