CVE-2023-34958: Medium severity Chamilo Chamilo LMS vulnerability
Published Jun 8, 2023
·Updated
Incorrect access control in Chamilo 1.11. up to 1.11.18 allows a student subscribed to a given course to download documents belonging to another student if they know the document's ID.
Affected Software
1 affected component
Chamilo Chamilo LMS>=1.11.0<=1.11.18
Remediation
Event History
Jun 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-34958?
CVE-2023-34958 is a vulnerability in Chamilo 1.11.* up to 1.11.18 that allows a student to download documents belonging to another student.
2
What is the severity of CVE-2023-34958?
CVE-2023-34958 has a severity level of medium.
3
How does CVE-2023-34958 occur?
CVE-2023-34958 occurs due to incorrect access control in Chamilo 1.11.* up to 1.11.18.
4
Which software versions are affected by CVE-2023-34958?
Chamilo versions 1.11.0 through 1.11.18 are affected by CVE-2023-34958.
5
How can I fix CVE-2023-34958?
To fix CVE-2023-34958, you should update Chamilo to a version higher than 1.11.18.