CVE-2023-4226: Chamilo LMS File Upload Functionality Remote Code Execution
Published Nov 28, 2023
·Updated
Unrestricted file upload in /main/inc/ajax/work.ajax.php in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
Affected Software
1 affected component
Chamilo Chamilo LMS<=1.11.24
Remediation
Event History
Nov 28, 2023
CVE Published
07:21 AM
Data Sourced
07:21 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-4226.
2
What is the affected software?
The affected software is Chamilo LMS v1.11.24 and below.
3
What is the severity of CVE-2023-4226?
The severity of CVE-2023-4226 is high with a severity value of 8.8.
4
How does this vulnerability occur?
This vulnerability occurs due to unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS.
5
How can an attacker exploit this vulnerability?
Authenticated attackers with the learner role can exploit this vulnerability by uploading PHP files to achieve remote code execution.