CVE-2023-4220

HIGH EXPLOITED NUCLEI

Chamilo v1.11.24 Unrestricted File Upload PHP Webshell

Title source: metasploit

Description

Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.

Exploits (32)

exploitdb WORKING POC
by Mohamed Kamel BOUZEKRIA · pythonwebappsphp
https://www.exploit-db.com/exploits/52083
nomisec WORKING POC 5 stars
by Rai2en · remote
https://github.com/Rai2en/CVE-2023-4220-Chamilo-LMS
nomisec WORKING POC 5 stars
by Ziad-Sakr · remote
https://github.com/Ziad-Sakr/Chamilo-CVE-2023-4220-Exploit
nomisec WORKING POC 1 stars
by zora-beep · remote
https://github.com/zora-beep/CVE-2023-4220
nomisec WORKING POC 1 stars
by Pr1or95 · remote
https://github.com/Pr1or95/CVE-2023-4220-exploit
nomisec WORKING POC 1 stars
by oxapavan · remote
https://github.com/oxapavan/CVE-2023-4220-HTB-PermX
nomisec WORKING POC 1 stars
by thefizzyfish · remote
https://github.com/thefizzyfish/CVE-2023-4220_Chamilo_RCE
nomisec WORKING POC 1 stars
by 0x00-null · remote
https://github.com/0x00-null/Chamilo-CVE-2023-4220-RCE-Exploit
nomisec WORKING POC 1 stars
by N1ghtfallXxX · remote
https://github.com/N1ghtfallXxX/CVE-2023-4220
nomisec NO CODE 1 stars
by charlesgargasson · remote
https://github.com/charlesgargasson/CVE-2023-4220
nomisec WORKING POC 1 stars
by dollarboysushil · remote
https://github.com/dollarboysushil/Chamilo-LMS-Unauthenticated-File-Upload-CVE-2023-4220
nomisec WORKING POC
by Sn0wBaall · remote
https://github.com/Sn0wBaall/CVE-2023-4220-PoC
nomisec WORKING POC
by Least-Significant-Bit · remote
https://github.com/Least-Significant-Bit/CVE-2023-4220
nomisec WORKING POC
by 0xDTC · remote
https://github.com/0xDTC/Chamilo-LMS-CVE-2023-4220-Exploit
nomisec WORKING POC
by numaan911098 · remote
https://github.com/numaan911098/CVE-2023-4220
nomisec WORKING POC
by H4cking4All · remote
https://github.com/H4cking4All/CVE-2023-4220
nomisec WORKING POC
by bueno-armando · remote
https://github.com/bueno-armando/CVE-2023-4220-RCE
nomisec WORKING POC
by VanishedPeople · remote
https://github.com/VanishedPeople/CVE-2023-4220
nomisec STUB
by qrxnz · poc
https://github.com/qrxnz/CVE-2023-4220
nomisec WORKING POC
by LGenAgul · remote
https://github.com/LGenAgul/CVE-2023-4220-Proof-of-concept
nomisec WORKING POC
by charchit-subedi · remote
https://github.com/charchit-subedi/chamilo-lms-unauthenticated-rce-poc
nomisec WORKING POC
by gmh5225 · remote
https://github.com/gmh5225/CVE-2023-4220
nomisec WORKING POC
by m3m0o · remote
https://github.com/m3m0o/chamilo-lms-unauthenticated-big-upload-rce-poc
github WORKING POC
by dugisan3rd · pythonpoc
https://github.com/dugisan3rd/exploit/tree/main/CVE-2023-4220_chamilo_file_upload
nomisec WORKING POC
by Al3xGD · remote
https://github.com/Al3xGD/CVE-2023-4220-Exploit
nomisec WORKING POC
by nr4x4 · remote
https://github.com/nr4x4/CVE-2023-4220
nomisec WORKING POC
by HO4XXX · remote
https://github.com/HO4XXX/cve-2023-4220-poc
vulncheck_xdb WRITEUP
remote
https://github.com/Sahil-Makhija/CVE-reports-from-Perplexity
vulncheck_xdb WORKING POC
remote
https://github.com/krishnan-tech/CVE-2023-4226-POC
metasploit WORKING POC EXCELLENT
by Ngo Wei Lin, jheysel-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/chamilo_bigupload_webshell.rb

Nuclei Templates (1)

Chamilo LMS <= 1.11.24 - Remote Code Execution
MEDIUMby s4e-io
Shodan: X-Powered-By: Chamilo

Scores

CVSS v3 8.1
EPSS 0.9324
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2024-12-05
CWE
CWE-434 CWE-79
Status published
Products (1)
chamilo/chamilo_lms < 1.11.24
Published Nov 28, 2023
Tracked Since Feb 18, 2026