Author: Angelo Barbosa

CVE-2023-4220 | Chamilo LMS up to 1.11.24 bigUpload.php unrestricted upload

A vulnerability has been found in Chamilo LMS up to 1.11.24 and classified as critical. Affected by this vulnerability is an unknown functionality in the library /main/inc/lib/javascript/bigupload/inc/bigUpload.php. The manipulation leads to unrestricted upload. This vulnerability is known as CVE-2023-4220. The attack can be launched remotely. There is no exploit...

Read More

CVE-2023-3368 | Chamilo LMS up to 1.11.20 additional_webservices.php os command injection

A vulnerability, which was classified as critical, was found in Chamilo LMS up to 1.11.20. Affected is an unknown function of the file /main/webservices/additional_webservices.php. The manipulation leads to os command injection. This vulnerability is traded as CVE-2023-3368. It is possible to launch the attack remotely. There is no exploit available. It is recommended to apply a patch to fix this...

Read More

CVE-2023-4222 | Chamilo LMS up to 1.11.24 openoffice_text_document.class.php os command injection

A vulnerability, which was classified as critical, has been found in Chamilo LMS up to 1.11.24. This issue affects some unknown processing of the file main/lp/openoffice_text_document.class.php. The manipulation leads to os command injection. The identification of this vulnerability is CVE-2023-4222. The attack may be initiated remotely. There is no exploit...

Read More