Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-3545

Опубликовано: 28 нояб. 2023
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Improper sanitisation in main/inc/lib/fileUpload.lib.php in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of .htaccess file. This vulnerability may be exploited by privileged attackers or chained with unauthenticated arbitrary file write vulnerabilities, such as CVE-2023-3533, to achieve remote code execution.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:chamilo:chamilo:*:*:*:*:*:*:*:*
Версия до 1.11.20 (включая)

EPSS

Процентиль: 86%
0.02987
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-178
CWE-178

Связанные уязвимости

CVSS3: 9.8
github
около 2 лет назад

Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `.htaccess` file. This vulnerability may be exploited by privileged attackers or chained with unauthenticated arbitrary file write vulnerabilities, such as CVE-2023-3533, to achieve remote code execution.

EPSS

Процентиль: 86%
0.02987
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-178
CWE-178