An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file.
References
Configurations
History
21 Nov 2024, 08:07
Type | Values Removed | Values Added |
---|---|---|
References | () http://chamilo.com - Product | |
References | () https://github.com/chamilo/chamilo-lms/commit/0d0c88c4806280ac9b70a299d6e3099269c9bc54 - Patch | |
References | () https://github.com/chamilo/chamilo-lms/commit/f6e83550c2d17fc93a65ec4be602a78312289f37 - Patch | |
References | () https://support.chamilo.org/projects/chamilo-18/wiki/Security_issues#Issue-113-2023-05-31-Low-impact-Low-risk-XSS-through-SVG - Vendor Advisory |
20 Jun 2023, 17:15
Type | Values Removed | Values Added |
---|---|---|
First Time |
Chamilo
Chamilo chamilo Lms |
|
CPE | cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:* | |
References | (MISC) https://support.chamilo.org/projects/chamilo-18/wiki/Security_issues#Issue-113-2023-05-31-Low-impact-Low-risk-XSS-through-SVG - Vendor Advisory | |
References | (MISC) https://github.com/chamilo/chamilo-lms/commit/f6e83550c2d17fc93a65ec4be602a78312289f37 - Patch | |
References | (MISC) https://github.com/chamilo/chamilo-lms/commit/0d0c88c4806280ac9b70a299d6e3099269c9bc54 - Patch | |
References | (MISC) http://chamilo.com - Product | |
CWE | CWE-434 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
13 Jun 2023, 21:27
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-13 21:15
Updated : 2024-11-21 08:07
NVD link : CVE-2023-34944
Mitre link : CVE-2023-34944
CVE.ORG link : CVE-2023-34944
JSON object : View
Products Affected
chamilo
- chamilo_lms
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type