Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qrrc-369r-8grr

Опубликовано: 28 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Improper sanitisation in main/inc/lib/fileUpload.lib.php in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of .htaccess file. This vulnerability may be exploited by privileged attackers or chained with unauthenticated arbitrary file write vulnerabilities, such as CVE-2023-3533, to achieve remote code execution.

Improper sanitisation in main/inc/lib/fileUpload.lib.php in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of .htaccess file. This vulnerability may be exploited by privileged attackers or chained with unauthenticated arbitrary file write vulnerabilities, such as CVE-2023-3533, to achieve remote code execution.

EPSS

Процентиль: 86%
0.02987
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-178

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 лет назад

Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `.htaccess` file. This vulnerability may be exploited by privileged attackers or chained with unauthenticated arbitrary file write vulnerabilities, such as CVE-2023-3533, to achieve remote code execution.

EPSS

Процентиль: 86%
0.02987
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-178