Chamilo-LMS-Unauthenticated-File-Upload-CVE-2023-4220. Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.

github.com/dollarboysushil/Chamilo-LMS-Unauthenticated-File-Upload-CVE-2023-4220

Vaya's read on this project

Problem, audience, market, and the verdict — sign in to see it.

Updates

No recent activity.