CVE-2023-4225: Chamilo LMS File Upload Functionality Remote Code Execution
Published Nov 28, 2023
·Updated
Unrestricted file upload in /main/inc/ajax/exercise.ajax.php in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
Affected Software
1 affected component
Chamilo Chamilo LMS<=1.11.24
Remediation
Event History
Nov 28, 2023
CVE Published
07:22 AM
Data Sourced
07:22 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-4225?
CVE-2023-4225 is a vulnerability in Chamilo LMS <= v1.11.24 that allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
2
How severe is CVE-2023-4225?
CVE-2023-4225 has a severity rating of 8.8 (high).
3
How does CVE-2023-4225 affect Chamilo LMS users?
CVE-2023-4225 affects Chamilo LMS users with versions up to v1.11.24.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-4225?
CVE-2023-4225 is associated with CWE-434.
5
How can CVE-2023-4225 be fixed?
To fix CVE-2023-4225, users should update their Chamilo LMS installation to a version beyond v1.11.24.