Chamilo LMS Unauthenticated Command Injection
CVE-2023-3368
9.8CRITICAL
What is CVE-2023-3368?
A command injection vulnerability exists in the Chamilo LMS software, specifically in the script located at /main/webservices/additional_webservices.php
. This flaw allows an unauthenticated attacker to execute arbitrary commands on the server, leading to potential remote code execution. The issue arises from the improper neutralization of special characters, which can be exploited without necessary user authentication. This vulnerability represents a significant risk, especially as it serves as a bypass for previously identified security issues.
Affected Version(s)
Chamilo 0 <= 1.11.20
References
EPSS Score
88% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ngo Wei Lin (@Creastery) of STAR Labs SG Pte. Ltd. (@starlabs_sg)