Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

FluxContactConfidentialité© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
CVE-2026-45140 — Disclosure pack and PoC script for CVE-2026-45140, an unauthenticated path traversal and RCE in Chamilo LMS CStudio upload, with a loopback Docker lab and patch guidance. | Kitploit
Outils/GitHubGitHub/abraxas/cve-2026-45140
Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingLearning & EducationLabs & Practice
GitHubabraxas/cve-2026-45140

CVE-2026-45140

Disclosure pack and PoC script for CVE-2026-45140, an unauthenticated path traversal and RCE in Chamilo LMS CStudio upload, with a loopback Docker lab and patch guidance.

36il y a 8 joursPas encore vérifié
Voir le dépôt

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
Contenu non disponible dans la langue demandée. Affichage de la version anglaise.

Abraxas Labs - CVE-2026-45140

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-45140

CVE-2026-45140

Chamilo LMS 2.0.0 - chamilo

I am @abraxas_null. Loopback lab. The client is CVE-2026-45140-Abraxas-Labs.py.

The advisory did not name the file. Unauthenticated RCE via leftover CStudio big-upload.php. key is concatenated onto cacheDir/cstudio_upload/ with no sanitization. action=upload appends php://input there. Traverse into public/. 2.0.0 has no api_get_user_id() on that script. Patched in 2.0.1 (403 + disable_dangerous_file).

CVECVE-2026-45140 · CVE.org
CWECWE-22, CWE-94, CWE-219, CWE-434
CVSSCritical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProductChamilo LMS
Affectedall versions through 2.0.0 (inclusive)
Patched2.0.1 and later
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

POST the plugin path with action=upload and a key that walks into public/. Body is attacker bytes. GET the written file. Writing .php under public/ is RCE. The lab witness is .txt because fopen appends and a second <?php in the same file is a parse error.


How I found it

The GHSA named RCE and not the path. I grepped CStudio for uploads, then read setTempName and uploadFile. This is not a Symfony action=. It is a leftover chunked-upload script under public/plugin.

POST, then GET. {"key":"...poc-witness.txt","errorStatus":0} is the router matching. Then GET /poc-witness.txt.

Wrong turns: hitting a Symfony route; 302 to /main/install/index.php because APP_INSTALLED is not 1; 403 JSON Forbidden on 2.0.1; GET without action=upload; writing .php twice and calling the parse error a miss.


The lab

Port 8088. Chamilo LMS 2.0.0 installed (APP_INSTALLED=1). CStudio plugin files under public/plugin/CStudio.

  • lab/Dockerfile
  • lab/apache-lab.conf
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-45140-Abraxas-Labs.py

Witness: GET /poc-witness.txt contains POCWitness45140. Installer HTML or 403 JSON is not it.

Ways to lose without learning anything:

  • 302 installer
  • 403 on 2.0.1
  • theme HTML without the file
  • reverse shell

The fix

Update Chamilo LMS to 2.0.1 or newer. Re-run CVE-2026-45140-Abraxas-Labs.py against the patched build: POCWitness45140 must not appear.


References

  • CVE-2026-45140 · NVD

  • CVE-2026-45140 · CVE.org

  • github.com/chamilo/chamilo-lms/commit/4bdba1b9a8820bd70c0809317775d7f6eaa79844

  • github.com/chamilo/chamilo-lms/releases/tag/v2.0.1

  • github.com/chamilo/chamilo-lms/security/advisories/GHSA-g4c3-4g96-6g4m

  • github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45140.json

  • nvd.nist.gov/vuln/detail/CVE-2026-45140

  • github.com/advisories/GHSA-g4c3-4g96-6g4m

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

Télécharger l’outil