Description
Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54097 | Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files. |
References
History
No history.
Status: PUBLISHED
Assigner: STAR_Labs
Published:
Updated: 2024-08-02T07:17:12.200Z
Reserved: 2023-08-08T06:52:32.927Z
Link: CVE-2023-4224
No data.
Status : Modified
Published: 2023-11-28T08:15:09.213
Modified: 2024-11-21T08:34:39.590
Link: CVE-2023-4224
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD