Description
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 23 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-23T20:44:14.630Z
Reserved: 2023-06-07T00:00:00.000Z
Link: CVE-2023-34960
Updated: 2024-08-02T16:17:04.267Z
Status : Modified
Published: 2023-08-01T02:15:10.307
Modified: 2024-11-21T08:07:43.457
Link: CVE-2023-34960
No data.
OpenCVE Enrichment
No data.
Weaknesses