CVE-2023-4222: Chamilo LMS Learning Path PPT2LP Command Injection Vulnerability
Command injection in main/lp/openofficetextdocument.class.php in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-4222?
CVE-2023-4222 is a Command Injection vulnerability in Chamilo LMS.
How does CVE-2023-4222 affect Chamilo LMS?
CVE-2023-4222 allows users permitted to upload Learning Paths in Chamilo LMS <= v1.11.24 to obtain remote code execution.
How severe is CVE-2023-4222?
CVE-2023-4222 has a severity score of 8.8 (high).
How can I fix or mitigate CVE-2023-4222?
To mitigate CVE-2023-4222, users should upgrade Chamilo LMS to a version higher than 1.11.24.
Where can I find more information about CVE-2023-4222?
You can find more information about CVE-2023-4222 in the references provided: [Link 1](https://support.chamilo.org/projects/chamilo-18/wiki/security_issues#Issue-128-2023-09-04-Critical-impact-Moderate-risk-Authenticated-users-may-gain-unauthenticated-RCE-CVE-2023-4221CVE-2023-4222) [Link 2](https://starlabs.sg/advisories/23/23-4222) [Link 3](https://github.com/chamilo/chamilo-lms/commit/ed72914608d2a07ee2eb587c1a654480d08201db).