icon

We found results for “

CVE-2023-3545

Date: November 28, 2023

Improper sanitisation in "main/inc/lib/fileUpload.lib.php" in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of ".htaccess" file. This vulnerability may be exploited by privileged attackers or chained with unauthenticated arbitrary file write vulnerabilities, such as CVE-2023-3533, to achieve remote code execution.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Improper Handling of Case Sensitivity

CWE-178

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

Do you need more information?

Contact Us