Description
Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54098 | Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files. |
References
History
Thu, 05 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chamilo chamilo
|
|
| CPEs | cpe:2.3:a:chamilo:chamilo:1.11.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Chamilo chamilo
|
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: STAR_Labs
Published:
Updated: 2025-06-05T13:54:07.400Z
Reserved: 2023-08-08T06:52:34.311Z
Link: CVE-2023-4225
Updated: 2024-08-02T07:17:12.131Z
Status : Modified
Published: 2023-11-28T08:15:09.607
Modified: 2024-11-21T08:34:39.723
Link: CVE-2023-4225
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD