Description
Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `.htaccess` file. This vulnerability may be exploited by privileged attackers or chained with unauthenticated arbitrary file write vulnerabilities, such as CVE-2023-3533, to achieve remote code execution.
Remediation
References
Related Vulnerabilities
Plone CMS Weak Password Requirements Vulnerability (CVE-2020-7940)
WordPress Plugin Podcast Importer SecondLine SQL Injection (1.3.7)
XOOPS Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-4851)
phpBB URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2015-3880)