CVE-2023-4221: Chamilo LMS Learning Path PPT2LP Command Injection Vulnerability
Command injection in main/lp/openofficepresentation.class.php in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-4221 vulnerability?
CVE-2023-4221 vulnerability is a command injection vulnerability in Chamilo LMS that allows users with upload permissions to execute remote code.
What is the severity of CVE-2023-4221?
The severity of CVE-2023-4221 is rated as high with a severity score of 8.8.
How does CVE-2023-4221 impact Chamilo LMS?
CVE-2023-4221 allows authenticated users to gain unauthenticated remote code execution, posing a critical impact and moderate risk to Chamilo LMS.
How can CVE-2023-4221 be exploited?
CVE-2023-4221 can be exploited by uploading a specially crafted Learning Path that contains a command injection payload.
Is there a fix available for CVE-2023-4221?
Yes, a fix for CVE-2023-4221 is available. It is recommended to update Chamilo LMS to a version that is not affected by the vulnerability.