Chamilo Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) Vulnerability - CVE-2023-4221 - Vulnerability Database

Chamilo Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) Vulnerability - CVE-2023-4221

High
Reference: CVE-2023-4221
Title: Chamilo Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) Vulnerability
Overview:

Command injection in main/lp/openoffice_presentation.class.php in Chamilo LMS lt v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.