Chamilo Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) Vulnerability - CVE-2023-4221
Command injection in main/lp/openoffice_presentation.class.php in Chamilo LMS lt v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.