← Back to browse · API

CVE-2023-3545

Severity
CRITICAL
CVSS
9.8
EPSS
0.01963
Risk score
39.89
CISA KEV
No
PoC
No
Published
2023-11-28
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2023-44201, GHSA-QRRC-369R-8GRR
Products
Chamilo:Chamilo 0 ≤1.11.20
Sources
euvd EUVD-2023-44201

Description

Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `.htaccess` file. This vulnerability may be exploited by privileged attackers or chained with unauthenticated arbitrary file write vulnerabilities, such as CVE-2023-3533, to achieve remote code execution.

References