CVE-2023-34960
01.08.2023, 02:15
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.
Vendor | Product | Version |
---|---|---|
chamilo | chamilo | 1.11.0 ≤ 𝑥 ≤ 1.11.18 |
𝑥
= Vulnerable software versions
References