Chamilo LMS Unauthenticated Command Injection
CVE-2023-3368

9.8CRITICAL

Key Information:

Vendor

Chamilo

Status
Vendor
CVE Published:
28 November 2023

What is CVE-2023-3368?

A command injection vulnerability exists in the Chamilo LMS software, specifically in the script located at /main/webservices/additional_webservices.php. This flaw allows an unauthenticated attacker to execute arbitrary commands on the server, leading to potential remote code execution. The issue arises from the improper neutralization of special characters, which can be exploited without necessary user authentication. This vulnerability represents a significant risk, especially as it serves as a bypass for previously identified security issues.

Affected Version(s)

Chamilo 0 <= 1.11.20

References

EPSS Score

88% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ngo Wei Lin (@Creastery) of STAR Labs SG Pte. Ltd. (@starlabs_sg)
.