Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

الخلاصاتاتصالالخصوصية© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2026-45140 — Disclosure pack and PoC script for CVE-2026-45140, an unauthenticated path traversal and RCE in Chamilo LMS CStudio upload, with a loopback Docker lab and patch guidance. | Kitploit
أدوات/GitHubGitHub/abraxas/cve-2026-45140
Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingLearning & EducationLabs & Practice
GitHubabraxas/cve-2026-45140

CVE-2026-45140

Disclosure pack and PoC script for CVE-2026-45140, an unauthenticated path traversal and RCE in Chamilo LMS CStudio upload, with a loopback Docker lab and patch guidance.

36منذ 8 أياملم تتم المراجعة بعد
عرض المستودع

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

Abraxas Labs - CVE-2026-45140

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-45140

CVE-2026-45140

Chamilo LMS 2.0.0 - chamilo

I am @abraxas_null. Loopback lab. The client is CVE-2026-45140-Abraxas-Labs.py.

The advisory did not name the file. Unauthenticated RCE via leftover CStudio big-upload.php. key is concatenated onto cacheDir/cstudio_upload/ with no sanitization. action=upload appends php://input there. Traverse into public/. 2.0.0 has no api_get_user_id() on that script. Patched in 2.0.1 (403 + disable_dangerous_file).

CVECVE-2026-45140 · CVE.org
CWECWE-22, CWE-94, CWE-219, CWE-434
CVSSCritical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProductChamilo LMS
Affectedall versions through 2.0.0 (inclusive)
Patched2.0.1 and later
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

POST the plugin path with action=upload and a key that walks into public/. Body is attacker bytes. GET the written file. Writing .php under public/ is RCE. The lab witness is .txt because fopen appends and a second <?php in the same file is a parse error.


How I found it

The GHSA named RCE and not the path. I grepped CStudio for uploads, then read setTempName and uploadFile. This is not a Symfony action=. It is a leftover chunked-upload script under public/plugin.

POST, then GET. {"key":"...poc-witness.txt","errorStatus":0} is the router matching. Then GET /poc-witness.txt.

Wrong turns: hitting a Symfony route; 302 to /main/install/index.php because APP_INSTALLED is not 1; 403 JSON Forbidden on 2.0.1; GET without action=upload; writing .php twice and calling the parse error a miss.


The lab

Port 8088. Chamilo LMS 2.0.0 installed (APP_INSTALLED=1). CStudio plugin files under public/plugin/CStudio.

  • lab/Dockerfile
  • lab/apache-lab.conf
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-45140-Abraxas-Labs.py

Witness: GET /poc-witness.txt contains POCWitness45140. Installer HTML or 403 JSON is not it.

Ways to lose without learning anything:

  • 302 installer
  • 403 on 2.0.1
  • theme HTML without the file
  • reverse shell

The fix

Update Chamilo LMS to 2.0.1 or newer. Re-run CVE-2026-45140-Abraxas-Labs.py against the patched build: POCWitness45140 must not appear.


References

  • CVE-2026-45140 · NVD

  • CVE-2026-45140 · CVE.org

  • github.com/chamilo/chamilo-lms/commit/4bdba1b9a8820bd70c0809317775d7f6eaa79844

  • github.com/chamilo/chamilo-lms/releases/tag/v2.0.1

  • github.com/chamilo/chamilo-lms/security/advisories/GHSA-g4c3-4g96-6g4m

  • github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45140.json

  • nvd.nist.gov/vuln/detail/CVE-2026-45140

  • github.com/advisories/GHSA-g4c3-4g96-6g4m

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

تنزيل الأداة