Description
Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `.htaccess` file. This vulnerability may be exploited by privileged attackers or chained with unauthenticated arbitrary file write vulnerabilities, such as CVE-2023-3533, to achieve remote code execution.
Remediation
References
Related Vulnerabilities
WordPress Plugin Favicon by RealFaviconGenerator Cross-Site Scripting (1.3.20)
MySQL CVE-2020-2924 Vulnerability (CVE-2020-2924)
WordPress Plugin Breezing Forms SQL Injection (1.2.7.30)
WordPress Plugin WooCommerce Conversion Tracking Cross-Site Request Forgery (2.0.4)
Dot CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-3688)