vendor:
Chamilo LMS
by:
0x00-null - Mohamed Kamel BOUZEKRIA
7.1
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: Chamilo LMS
Affected Version From: 1.11.24
Affected Version To: 1.11.24
Patch Exists: NO
Related CWE: CVE-2023-4220
CPE: a:chamilo:chamilo_lms:1.11.24
Platforms Tested: Web Application
2024
Chamilo LMS 1.11.24 – Remote Code Execution (RCE)
Unauthenticated remote code execution vulnerability in Chamilo LMS version 1.11.24 (Beersel) allows attackers to upload files without restrictions, leading to remote code execution.
Mitigation:
Ensure the directory /main/inc/lib/javascript/bigupload/files/ exists and is not writable by unauthorized users.