CVE-2023-3368
28.11.2023, 07:15
Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960.
Vendor | Product | Version |
---|---|---|
chamilo | chamilo | 𝑥 < 1.11.20 |
𝑥
= Vulnerable software versions
References