First published: Tue Nov 28 2023(Updated: )
Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
Credit: info@starlabs.sg
Affected Software | Affected Version | How to fix |
---|---|---|
Chamilo Chamilo Lms | <=1.11.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-4226.
The affected software is Chamilo LMS v1.11.24 and below.
The severity of CVE-2023-4226 is high with a severity value of 8.8.
This vulnerability occurs due to unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS.
Authenticated attackers with the learner role can exploit this vulnerability by uploading PHP files to achieve remote code execution.