Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `.htaccess` file. This vulnerability may be exploited by privileged attackers or chained with unauthenticated arbitrary file write vulnerabilities, such as CVE-2023-3533, to achieve remote code execution.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: STAR_Labs

Published: 2023-11-28T07:07:27.183Z

Updated: 2024-08-02T07:01:57.437Z

Reserved: 2023-07-07T13:10:48.745Z

Link: CVE-2023-3545

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-11-28T07:15:42.913

Modified: 2023-12-04T18:50:46.923

Link: CVE-2023-3545

cve-icon Redhat

No data.