CVE-2023-4220
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Chamilo · Chamilopublic PoCs found — 27
githubgithub.com/Ziad-Sakr/Chamilo-CVE-2023-4220-Exploit★ 5githubgithub.com/Rai2en/CVE-2023-4220-Chamilo-LMS★ 5githubgithub.com/charlesgargasson/CVE-2023-4220★ 1githubgithub.com/Pr1or95/CVE-2023-4220-exploit★ 1githubgithub.com/dollarboysushil/Chamilo-LMS-Unauthenticated-File-Upload-CVE-2023-4220★ 1githubgithub.com/thefizzyfish/CVE-2023-4220_Chamilo_RCE★ 1githubgithub.com/0x00-null/Chamilo-CVE-2023-4220-RCE-Exploit★ 1githubgithub.com/bueno-armando/CVE-2023-4220-RCE★ 1githubgithub.com/oxapavan/CVE-2023-4220-HTB-PermX★ 1githubgithub.com/zora-beep/CVE-2023-4220★ 1githubgithub.com/N1ghtfallXxX/CVE-2023-4220★ 1githubgithub.com/charchit-subedi/chamilo-lms-unauthenticated-rce-poc★ 0githubgithub.com/VanishedPeople/CVE-2023-4220★ 0githubgithub.com/LGenAgul/CVE-2023-4220-Proof-of-concept★ 0githubgithub.com/qrxnz/CVE-2023-4220★ 0githubgithub.com/Least-Significant-Bit/CVE-2023-4220★ 0githubgithub.com/Sn0wBaall/CVE-2023-4220-PoC★ 0githubgithub.com/0xDTC/Chamilo-LMS-CVE-2023-4220-Exploit★ 0githubgithub.com/H4cking4All/CVE-2023-4220★ 0githubgithub.com/SpeatX/ChamiloLMS-CVE-2023-4220★ 0githubgithub.com/numaan911098/CVE-2023-4220★ 0githubgithub.com/m3m0o/chamilo-lms-unauthenticated-big-upload-rce-poc★ 0githubgithub.com/HO4XXX/cve-2023-4220-poc★ 0githubgithub.com/nr4x4/CVE-2023-4220★ 0githubgithub.com/Al3xGD/CVE-2023-4220-Exploit★ 0githubgithub.com/gmh5225/CVE-2023-4220★ 0exploitdbwww.exploit-db.com/exploits/52083unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://github.com/chamilo/chamilo-lms/commit/3b487a55076fb06f96809b790a35dcdd42f8ec49https://starlabs.sg/advisories/23/23-4220https://support.chamilo.org/projects/chamilo-18/wiki/security_issues#Issue-130-2023-09-04-Critical-impact-High-risk-Unauthenticated-users-may-gain-XSS-and-unauthenticated-RCE-CVE-2023-4220