Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
100Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 8.1epss 76%
from disclosure to weapon222 days
Published on NVDNov 28
1st PoC+222d
metasploitNov 28
VulnCheck+373d
exploitation probability
76%top 1% of all CVEs
observed exploitation
yesVulnCheck
59 public exploit(s)
Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Chamilo · Chamilopublic PoCs found — 59
exploitdbwww.exploit-db.com/exploits/52083unverifiedgithubgithub.com/Rai2en/CVE-2023-4220-Chamilo-LMS★ 5githubgithub.com/Ziad-Sakr/Chamilo-CVE-2023-4220-Exploit★ 5githubgithub.com/oxapavan/CVE-2023-4220-HTB-PermX★ 1githubgithub.com/thefizzyfish/CVE-2023-4220_Chamilo_RCE★ 1githubgithub.com/0x00-null/Chamilo-CVE-2023-4220-RCE-Exploit★ 1githubgithub.com/bueno-armando/CVE-2023-4220-RCE★ 1githubgithub.com/N1ghtfallXxX/CVE-2023-4220★ 1githubgithub.com/dollarboysushil/Chamilo-LMS-Unauthenticated-File-Upload-CVE-2023-4220★ 1githubgithub.com/charlesgargasson/CVE-2023-4220★ 1githubgithub.com/Pr1or95/CVE-2023-4220-exploit★ 1githubgithub.com/zora-beep/CVE-2023-4220★ 1githubgithub.com/HO4XXX/cve-2023-4220-poc★ 0githubgithub.com/numaan911098/CVE-2023-4220★ 0githubgithub.com/m3m0o/chamilo-lms-unauthenticated-big-upload-rce-poc★ 0githubgithub.com/H4cking4All/CVE-2023-4220★ 0githubgithub.com/Least-Significant-Bit/CVE-2023-4220★ 0githubgithub.com/Sn0wBaall/CVE-2023-4220-PoC★ 0githubgithub.com/Al3xGD/CVE-2023-4220-Exploit★ 0githubgithub.com/charchit-subedi/chamilo-lms-unauthenticated-rce-poc★ 0githubgithub.com/nr4x4/CVE-2023-4220★ 0githubgithub.com/gmh5225/CVE-2023-4220★ 0githubgithub.com/LGenAgul/CVE-2023-4220-Proof-of-concept★ 0githubgithub.com/qrxnz/CVE-2023-4220★ 0githubgithub.com/VanishedPeople/CVE-2023-4220★ 0githubgithub.com/RandyNin/CVE-2023-4220★ 0githubgithub.com/0xDTC/Chamilo-LMS-CVE-2023-4220-Exploit★ 0githubgithub.com/SpeatX/ChamiloLMS-CVE-2023-4220★ 0vulncheckvulncheck.com/xdb/25efb2079caaunverifiedvulncheckvulncheck.com/xdb/4c0606dd5ec9unverifiedvulncheckvulncheck.com/xdb/cb759ddb54e4unverifiedvulncheckvulncheck.com/xdb/58994525cdd3unverifiedvulncheckvulncheck.com/xdb/bdc95ad9609bunverifiedvulncheckvulncheck.com/xdb/3b6cd44e17c6unverifiedvulncheckvulncheck.com/xdb/98271549c6eaunverifiedvulncheckvulncheck.com/xdb/21e1dfc97c59unverifiedvulncheckvulncheck.com/xdb/f69a1f008b0eunverifiedvulncheckvulncheck.com/xdb/6b78ca62a34cunverifiedvulncheckvulncheck.com/xdb/01cef89ac168unverifiedvulncheckvulncheck.com/xdb/51dcc188c2d6unverifiedvulncheckvulncheck.com/xdb/6f3b083d8a2aunverifiedvulncheckvulncheck.com/xdb/2fbc4336feacunverifiedvulncheckvulncheck.com/xdb/dae666e719cdunverifiedvulncheckvulncheck.com/xdb/e34138da6c04unverifiedvulncheckvulncheck.com/xdb/a40b98381b26unverifiedvulncheckvulncheck.com/xdb/630f4cc835a9unverifiedvulncheckvulncheck.com/xdb/bbbcb12a4a5bunverifiedvulncheckvulncheck.com/xdb/9fe6dd27f44cunverifiedvulncheckvulncheck.com/xdb/463dc3c4df19unverifiedvulncheckvulncheck.com/xdb/10ae6624b0dfunverifiedvulncheckvulncheck.com/xdb/9316b9d7e5bfunverifiedvulncheckvulncheck.com/xdb/00cdf7216db2unverifiedvulncheckvulncheck.com/xdb/80e50f659827unverifiedvulncheckvulncheck.com/xdb/344c5660e668unverifiedvulncheckvulncheck.com/xdb/3602eeac2b52unverifiedvulncheckvulncheck.com/xdb/2ecbe581c242unverifiedvulncheckvulncheck.com/xdb/20c77fa9263dunverifiedvulncheckvulncheck.com/xdb/cd29f0fcca93unverifiedvulncheckvulncheck.com/xdb/452fdfb79592unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://github.com/chamilo/chamilo-lms/commit/3b487a55076fb06f96809b790a35dcdd42f8ec49https://starlabs.sg/advisories/23/23-4220https://support.chamilo.org/projects/chamilo-18/wiki/security_issues#Issue-130-2023-09-04-Critical-impact-High-risk-Unauthenticated-users-may-gain-XSS-and-unauthenticated-RCE-CVE-2023-4220