First published: Tue Nov 28 2023(Updated: )
Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
Credit: info@starlabs.sg
Affected Software | Affected Version | How to fix |
---|---|---|
Chamilo Chamilo Lms | <=1.11.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4225 is a vulnerability in Chamilo LMS <= v1.11.24 that allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
CVE-2023-4225 has a severity rating of 8.8 (high).
CVE-2023-4225 affects Chamilo LMS users with versions up to v1.11.24.
CVE-2023-4225 is associated with CWE-434.
To fix CVE-2023-4225, users should update their Chamilo LMS installation to a version beyond v1.11.24.