Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-4220 — CVE-2023-4220 Chamilo Exploit | Kitploit
Tools/GitHubGitHub/h4cking4all/cve-2023-4220
Payload GenerationVulnerability AnalysisExploitationShellcodeWeb Application ExploitationRemote Access Tool
GitHubh4cking4all/cve-2023-4220

CVE-2023-4220

CVE-2023-4220 Chamilo Exploit

View Repository
81 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Chamilo CVE-2023-4220 Exploit

The CVE-2023-4220 vulnerability is a file upload vulnerability affecting Chamilo versions <= 1.11.24. This vulnerability allows an attacker to achieve remote command execution by uploading a webshell via the path /main/inc/lib/javascript/bigupload/inc/bigUpload.php, which will be stored in the /main/inc/lib/javascript/bigupload/files directory.

Installation

git clone https://github.com/H4cking4All/CVE-2023-4220.git
cd CVE-2023-4220
pip3 install requirements.txt

PoC

help

The script can be run in two modes: checkvuln, only to check if the system is vulnerable, and exploit, which will exploit the vulnerability by uploading a web shell and sending a reverse shell to the attacker's machine.

First, we listen with netcat:

nc

Then run the exploit:

exploit

Thus, we would receive an interactive shell:

revshell

Download Tool