Chamilo LMS fixed two high-severity command injection vulnerabilities, CVE-2023-4221 and CVE-2023-4222, that can allow remote code execution in versions up to and including 1.11.24. The bugs affect the learning path conversion workflow: CVE-2023-4221 is in main/lp/openoffice_presentation.class.php, where attacker-controlled slide_size input is passed into an OS command, while CVE-2023-4222 is in main/lp/openoffice_text_document.class.php, where a crafted uploaded filename containing shell metacharacters is used unsafely. In both cases, exploitation requires an authenticated user with permission to upload learning paths, such as a Trainer-role user, and depends on Chamilo RAPID being enabled with service_ppt2lp set to localhost.
STAR Labs said the flaws appear related to the previously disclosed Chamilo command injection issue CVE-2023-34960 and published proof-of-concept details showing exploitation through lp_upload.php and related upload endpoints using a non-empty ppt2lp or woogie parameter. Chamilo addressed the issues in v1.11.26. Defenders are advised to upgrade and review access logs, upload activity, and database records for suspicious learning path uploads, especially requests to upload endpoints containing unusual slide_size values, non-empty conversion parameters, or malicious filenames.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
STAR Labs publicly disclosed the two vulnerabilities, including technical root-cause details, affected components, exploitation prerequisites, and proof-of-concept information for CVE-2023-4221. The advisories also linked the bugs to the previously disclosed Chamilo command injection issue CVE-2023-34960 and provided detection guidance for defenders.
Chamilo addressed the command injection issues with a complete fix in version 1.11.26. The fixes cover the vulnerable code paths in both openoffice_presentation.class.php and openoffice_text_document.class.php.
Two related command injection vulnerabilities, CVE-2023-4221 and CVE-2023-4222, were identified in Chamilo LMS in learning path PPT2LP processing code. The flaws affect versions up to and including 1.11.24 and can allow remote code execution by authenticated users permitted to upload learning paths when Chamilo RAPID is enabled and service_ppt2lp is set to localhost.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
starlabs.sg
Open sourcestarlabs.sg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.