Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960.
References
Configurations
History
No history.
Information
Published : 2023-11-28 07:15
Updated : 2023-12-04 18:57
NVD link : CVE-2023-3368
Mitre link : CVE-2023-3368
CVE.ORG link : CVE-2023-3368
JSON object : View
Products Affected
chamilo
- chamilo
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')