cve/2023/CVE-2023-4222.md
2024-06-18 02:51:15 +02:00

826 B

CVE-2023-4222

Description

Command injection in main/lp/openoffice_text_document.class.php in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.

POC

Reference

Github

No PoCs found on GitHub currently.