CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-4225HIGH | Chamilo LMS File Upload Functionality Remote Code ExecutionUnrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files. CWE-434Nov 28, 2023 | CVSS8.8v3.1 | EPSS1.83% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4226HIGH | Chamilo LMS File Upload Functionality Remote Code ExecutionUnrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files. CWE-434Nov 28, 2023 | CVSS8.8v3.1 | EPSS2.43% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4224HIGH | Chamilo LMS File Upload Functionality Remote Code ExecutionUnrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files. CWE-434Nov 28, 2023 | CVSS8.8v3.1 | EPSS1.83% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4223HIGH | Chamilo LMS File Upload Functionality Remote Code ExecutionUnrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files. CWE-434Nov 28, 2023 | CVSS8.8v3.1 | EPSS1.83% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4222HIGH | Chamilo LMS Learning Path PPT2LP Command Injection VulnerabilityCommand injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters. CWE-78Nov 28, 2023 | CVSS7.2v3.1 | EPSS3.53% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4221HIGH | Chamilo LMS Learning Path PPT2LP Command Injection VulnerabilityCommand injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters. CWE-78Nov 28, 2023 | CVSS7.2v3.1 | EPSS3.53% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4220HIGH | Chamilo LMS Unauthenticated Big Upload File Remote Code ExecutionUnrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell. | CVSS8.1v3.1 | EPSS76.1% | PoCs30 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-3545CRITICAL | Chamilo LMS Htaccess File Upload Security BypassImproper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `.htaccess` file. This vulnerability may be exploited by privileged attackers or chained with unauthenticated arbitrary file write vulnerabilities, such as CVE-2023-3533, to achieve remote code execution. CWE-178Nov 28, 2023 | CVSS9.8v3.1 | EPSS1.96% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3533CRITICAL | Chamilo LMS Unauthenticated Remote Code Execution via Arbitrary File WritePath traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via arbitrary file write. CWE-22Nov 28, 2023 | CVSS9.8v3.1 | EPSS2.72% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3368CRITICAL | Chamilo LMS Unauthenticated Command InjectionCommand injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960. | CVSS9.8v3.1 | EPSS68.9% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-34960CRITICAL | chamilo chamilo Improper Neutralization of Special Elements used in a Command ('Command Injection')A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name. | CVSS9.8v3.1 | EPSS99.2% | PoCs9 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-34187CRITICAL | chamilo chamilo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter. | CVSS9.8v3.1 | EPSS16.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2013-0739MEDIUM | Chamilo 1.9.4 has XSS due to improper validation of user-supplied input by the chat.php script. CWE-79Jan 30, 2020 | CVSS6.1v3.1 | EPSS0.797% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2013-0738MEDIUM | Chamilo 1.9.4 has Multiple XSS and HTML Injection Vulnerabilities: blog.php and announcements.php. CWE-79Jan 30, 2020 | CVSS6.1v3.1 | EPSS0.797% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |