CVE-2023-4226
HIGH 8.8EPSS 2.4%
Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 2.43% chance of exploitation in the next 30 days, 83th percentile
- Published
- 2023-11-28
- Updated
- 2024-08-02
Proof-of-concept exploits (3)
- https://starlabs.sg/advisories/23/23-4226
- SkyW4r33x/CVE-2023-42261★ · 2025-05-25
- krishnan-tech/CVE-2023-4226-POC1★ · 2024-07-10