CVE-2023-3533: Chamilo LMS Unauthenticated Remote Code Execution via Arbitrary File Write
Path traversal in file upload functionality in /main/webservices/additionalwebservices.php in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via arbitrary file write.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-3533?
CVE-2023-3533 is a vulnerability in Chamilo LMS that allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via arbitrary file write.
How severe is CVE-2023-3533?
CVE-2023-3533 has a severity rating of critical with a score of 9.8.
Which versions of Chamilo LMS are affected by CVE-2023-3533?
Chamilo LMS versions up to and including v1.11.20 are affected by CVE-2023-3533.
How can an attacker exploit CVE-2023-3533?
An unauthenticated attacker can exploit CVE-2023-3533 by performing stored cross-site scripting attacks and obtaining remote code execution through arbitrary file write.
Where can I find more information about CVE-2023-3533?
You can find more information about CVE-2023-3533 at the following references: [Reference 1](https://support.chamilo.org/projects/chamilo-18/wiki/security_issues#Issue-124-2023-07-13-Critical-impact-High-risk-Unauthenticated-Arbitrary-File-Write-RCE-CVE-2023-3533), [Reference 2](https://starlabs.sg/advisories/23/23-3533/), [Reference 3](https://github.com/chamilo/chamilo-lms/commit/37be9ce7243a30259047dd4517c48ff8b21d657a).