First published: Tue Nov 28 2023(Updated: )
Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
Credit: info@starlabs.sg
Affected Software | Affected Version | How to fix |
---|---|---|
Chamilo Chamilo Lms | <=1.11.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4222 is a Command Injection vulnerability in Chamilo LMS.
CVE-2023-4222 allows users permitted to upload Learning Paths in Chamilo LMS <= v1.11.24 to obtain remote code execution.
CVE-2023-4222 has a severity score of 8.8 (high).
To mitigate CVE-2023-4222, users should upgrade Chamilo LMS to a version higher than 1.11.24.
You can find more information about CVE-2023-4222 in the references provided: [Link 1](https://support.chamilo.org/projects/chamilo-18/wiki/security_issues#Issue-128-2023-09-04-Critical-impact-Moderate-risk-Authenticated-users-may-gain-unauthenticated-RCE-CVE-2023-4221CVE-2023-4222) [Link 2](https://starlabs.sg/advisories/23/23-4222) [Link 3](https://github.com/chamilo/chamilo-lms/commit/ed72914608d2a07ee2eb587c1a654480d08201db).