- Description
- Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move function. The move() function in fileManage.lib.php passes user-controlled path values directly into exec() shell commands without using escapeshellarg(). When a user moves a document via document.php, the move_to POST parameter — which only passes through Security::remove_XSS() (an HTML-only filter) — is concatenated directly into shell commands such as exec("mv $source $target"). By default, Chamilo allows all authenticated users to create courses (allow_users_to_create_courses = true). Any user who is a teacher in a course (including self-created courses) can move documents, making this vulnerability exploitable by any authenticated user. The attacker must first place a directory with shell metacharacters in its name on the filesystem (achievable via Course Backup Import), then move a document into that directory to trigger arbitrary command execution as the web server user (www-data). This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- chamilo_lms
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- security-advisories@github.com
- CWE-78
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A4D0C5D2-6FA0-4532-8E3D-4EA111A50621",
"versionEndExcluding": "1.11.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha1:*:*:*:*:*:*",
"matchCriteriaId": "4AF7661F-C1F7-4CAB-BBDF-FC5BF7F5BEB8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha2:*:*:*:*:*:*",
"matchCriteriaId": "FE56AF71-9D53-42C6-980D-09E1C418ED87",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha3:*:*:*:*:*:*",
"matchCriteriaId": "01195674-9E1A-4C07-B7D3-0F0CC2E6511B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha4:*:*:*:*:*:*",
"matchCriteriaId": "BAE63449-5A56-4302-A4BF-F3D19FC96A80",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha5:*:*:*:*:*:*",
"matchCriteriaId": "A84A06F9-5AB7-4703-8153-33AC68882B95",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:chamilo:chamilo_lms:2.0.0:beta1:*:*:*:*:*:*",
"matchCriteriaId": "B91302A3-53DE-4ED0-BAAB-FE9DA03F8242",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:chamilo:chamilo_lms:2.0.0:beta2:*:*:*:*:*:*",
"matchCriteriaId": "46008D4A-96F7-4E04-8256-E115AAAE3383",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:chamilo:chamilo_lms:2.0.0:beta3:*:*:*:*:*:*",
"matchCriteriaId": "6E2BCAFF-D44B-4E67-998A-DF855E27606B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:chamilo:chamilo_lms:2.0.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "D2E7D018-E4C2-45F5-8D9A-DAC947173607",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:chamilo:chamilo_lms:2.0.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "DAF96697-6B6D-459D-9510-E5CEEDC2859B",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]