Chamilo LMS fixed multiple high-severity file upload vulnerabilities that allowed attackers to achieve remote code execution by abusing weak filename validation and unsafe handling of uploaded files. In CVE-2023-3545, affecting versions through 1.11.20, improper case-sensitive sanitization in fileUpload.lib.php let attackers on Windows servers running Apache bypass .htaccess upload protections with mixed-case filenames, then configure Apache to execute uploaded files as PHP. STAR Labs said the flaw could be exploited by authenticated users with the Trainer role or chained with an arbitrary file write bug such as CVE-2023-3533 for unauthenticated compromise; Chamilo fully addressed it in version 1.11.22.
A separate flaw, CVE-2023-4223, affected versions through 1.11.24 in /main/inc/ajax/document.ajax.php and allowed an authenticated learner to upload PHP files and overwrite .htaccess in the web-accessible /app/cache directory, leading to remote code execution and stored cross-site scripting. STAR Labs reported that user-controlled filenames were written into SYS_ARCHIVE_PATH without sufficient validation or dangerous file-type restrictions, and noted similar upload issues in related AJAX handlers tracked as CVE-2023-4224, CVE-2023-4225, and CVE-2023-4226. Chamilo released a complete fix for CVE-2023-4223 in version 1.11.26.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
STAR Labs SG disclosed technical details for CVE-2023-3545, a case-sensitive .htaccess upload bypass affecting Chamilo up to 1.11.20, and CVE-2023-4223, a learner-accessible file upload flaw affecting versions up to 1.11.24. The advisories described how the bugs could enable remote code execution on vulnerable deployments and noted that Chamilo had issued fixes, including version 1.11.22 for CVE-2023-3545.
Chamilo released version 1.11.26 on 2023-09-27 to fully fix CVE-2023-4223, an unrestricted file upload vulnerability in document.ajax.php that could lead to remote code execution. The advisory also noted similar upload issues in related AJAX handlers tracked as CVE-2023-4224, CVE-2023-4225, and CVE-2023-4226.
A Chamilo GitHub commit dated 2023-07-13 introduced a security change to rename .htaccess files using case-insensitive replacement. The change appears related to the later-documented .htaccess upload bypass issue tracked as CVE-2023-3545.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
starlabs.sg
Open sourcestarlabs.sg
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.