Chamilo LMS disclosed high-severity unrestricted file upload vulnerabilities, CVE-2023-4225 and CVE-2023-4226, in /main/inc/ajax/exercise.ajax.php and /main/inc/ajax/work.ajax.php. The flaws affect versions up to and including 1.11.24 and allow an authenticated user with learner privileges to upload arbitrary files into the web-accessible /app/cache directory. By uploading PHP files and modifying .htaccess, an attacker can enable code execution on the server and run commands with the web server's privileges; STAR Labs demonstrated exploitation with a PHP web shell executing as www-data.
The advisories said the vulnerable logic trusted user-supplied filenames without adequate restriction and noted similar issues in related Chamilo AJAX handlers tracked as CVE-2023-4223 and CVE-2023-4224. Beyond remote code execution, the same weakness can also support stored cross-site scripting through uploaded HTML content. Chamilo addressed the issues in version 1.11.26, and defenders were urged to review requests to the affected endpoints and access to /app/cache for signs of compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
STAR Labs SG published advisories for CVE-2023-4225 and CVE-2023-4226, detailing authenticated remote code execution vulnerabilities in Chamilo LMS upload functionality and noting related issues under CVE-2023-4223 and CVE-2023-4224. The disclosure included proof-of-concept exploitation details and noted publication was delayed during coordinated disclosure because of observed in-the-wild exploitation of another Chamilo N-day vulnerability, CVE-2023-34960.
Chamilo released version 1.11.26, which fully fixed unrestricted file upload vulnerabilities affecting AJAX endpoints including /main/inc/ajax/exercise.ajax.php and /main/inc/ajax/work.ajax.php in versions up to 1.11.24. The flaws allowed authenticated learner-level users to upload PHP files and manipulate .htaccess in /app/cache, enabling remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
starlabs.sg
Open sourcestarlabs.sg
Open sourcestarlabs.sg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.