CVE-2023-34960

Published Aug 1, 2023

Last updated a year ago

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2023-34960 is a command injection vulnerability found in the wsConvertPpt component of Chamilo Learning Management System (LMS) versions 1.11.* up to 1.11.18. This vulnerability allows attackers to execute arbitrary commands on the server. The vulnerability is exploitable through a specially crafted PowerPoint file name used in a SOAP API call to the wsConvertPpt component.

Description
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.
Source
cve@mitre.org
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

nvd@nist.gov
CWE-77

Social media

Hype score
Not currently trending

Configurations