CVE-2023-3545
Chamilo LMS Htaccess File Upload Security Bypass
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `.htaccess` file. This vulnerability may be exploited by privileged attackers or chained with unauthenticated arbitrary file write vulnerabilities, such as CVE-2023-3533, to achieve remote code execution.
La sanitización inadecuada en `main/inc/lib/fileUpload.lib.php` en Chamilo LMS en versiones <= 1.11.20 en instalaciones de Windows y Apache permite a atacantes no autenticados eludir las protecciones de seguridad de carga de archivos y obtener la ejecución remota de código mediante la carga de archivo `.htaccess`. Esta vulnerabilidad puede ser aprovechada por atacantes privilegiados o encadenada con vulnerabilidades de escritura de archivos arbitrarios no autenticados, como CVE-2023-3533, para lograr la ejecución remota de código.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-07-07 CVE Reserved
- 2023-11-28 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-12-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-178: Improper Handling of Case Sensitivity
CAPEC
- CAPEC-650: Upload a Web Shell to a Web Server
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://starlabs.sg/advisories/23/23-3545 | 2024-08-02 |
URL | Date | SRC |
---|---|---|
https://github.com/chamilo/chamilo-lms/commit/dc7bfce429fbd843a95a57c184b6992c4d709549 | 2023-12-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Chamilo Search vendor "Chamilo" | Chamilo Search vendor "Chamilo" for product "Chamilo" | <= 1.11.20 Search vendor "Chamilo" for product "Chamilo" and version " <= 1.11.20" | - |
Affected
|