Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-45140 — Disclosure pack and PoC script for CVE-2026-45140, an unauthenticated path traversal and RCE in Chamilo LMS CStudio upload, with a loopback Docker lab and patch guidance. | Kitploit
도구/GitHubGitHub/abraxas/cve-2026-45140
Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingLearning & EducationLabs & Practice
GitHubabraxas/cve-2026-45140

CVE-2026-45140

Disclosure pack and PoC script for CVE-2026-45140, an unauthenticated path traversal and RCE in Chamilo LMS CStudio upload, with a loopback Docker lab and patch guidance.

368일 전아직 검토되지 않음
저장소 보기

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

Abraxas Labs - CVE-2026-45140

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-45140

CVE-2026-45140

Chamilo LMS 2.0.0 - chamilo

I am @abraxas_null. Loopback lab. The client is CVE-2026-45140-Abraxas-Labs.py.

The advisory did not name the file. Unauthenticated RCE via leftover CStudio big-upload.php. key is concatenated onto cacheDir/cstudio_upload/ with no sanitization. action=upload appends php://input there. Traverse into public/. 2.0.0 has no api_get_user_id() on that script. Patched in 2.0.1 (403 + disable_dangerous_file).

CVECVE-2026-45140 · CVE.org
CWECWE-22, CWE-94, CWE-219, CWE-434
CVSSCritical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProductChamilo LMS
Affectedall versions through 2.0.0 (inclusive)
Patched2.0.1 and later
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

POST the plugin path with action=upload and a key that walks into public/. Body is attacker bytes. GET the written file. Writing .php under public/ is RCE. The lab witness is .txt because fopen appends and a second <?php in the same file is a parse error.


How I found it

The GHSA named RCE and not the path. I grepped CStudio for uploads, then read setTempName and uploadFile. This is not a Symfony action=. It is a leftover chunked-upload script under public/plugin.

POST, then GET. {"key":"...poc-witness.txt","errorStatus":0} is the router matching. Then GET /poc-witness.txt.

Wrong turns: hitting a Symfony route; 302 to /main/install/index.php because APP_INSTALLED is not 1; 403 JSON Forbidden on 2.0.1; GET without action=upload; writing .php twice and calling the parse error a miss.


The lab

Port 8088. Chamilo LMS 2.0.0 installed (APP_INSTALLED=1). CStudio plugin files under public/plugin/CStudio.

  • lab/Dockerfile
  • lab/apache-lab.conf
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-45140-Abraxas-Labs.py

Witness: GET /poc-witness.txt contains POCWitness45140. Installer HTML or 403 JSON is not it.

Ways to lose without learning anything:

  • 302 installer
  • 403 on 2.0.1
  • theme HTML without the file
  • reverse shell

The fix

Update Chamilo LMS to 2.0.1 or newer. Re-run CVE-2026-45140-Abraxas-Labs.py against the patched build: POCWitness45140 must not appear.


References

  • CVE-2026-45140 · NVD

  • CVE-2026-45140 · CVE.org

  • github.com/chamilo/chamilo-lms/commit/4bdba1b9a8820bd70c0809317775d7f6eaa79844

  • github.com/chamilo/chamilo-lms/releases/tag/v2.0.1

  • github.com/chamilo/chamilo-lms/security/advisories/GHSA-g4c3-4g96-6g4m

  • github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45140.json

  • nvd.nist.gov/vuln/detail/CVE-2026-45140

  • github.com/advisories/GHSA-g4c3-4g96-6g4m

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

도구 다운로드