Command injection in /main/webservices/additional_webservices.php in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960.
{
"cwe_ids": [
"CWE-78"
],
"cna_assigner": "STAR_Labs",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/3xxx/CVE-2023-3368.json"
}{
"cpe": "cpe:2.3:a:chamilo:chamilo:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.11.20"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}