rapid7 / metasploit-framework

Metasploit Framework
https://www.metasploit.com/
Other
34.25k stars 14k forks source link

Chamilo v1.11.24 Unrestricted File Upload PHP Webshell #19631

Open jheysel-r7 opened 2 weeks ago

jheysel-r7 commented 2 weeks ago

Summary

In versions prior to <= v1.11.24 a webshell can be uploaded via the bigload.php endpoint. If the GET request parameter action is set to post-unsupported file extension checks are skipped allowing for attacker controlled .php files to be uploaded

Basic example

https://github.com/H4cking4All/CVE-2023-4220/tree/main