CVE-2023-4221
Chamilo vulnerability analysis and mitigation

Overview

Command injection vulnerability (CVE-2023-4221) affects Chamilo LMS versions up to and including v1.11.24. The vulnerability exists in main/lp/openoffice_presentation.class.php and allows users with permissions to upload Learning Paths to obtain remote code execution through improper neutralization of special characters (STAR Labs).

Technical details

The vulnerability stems from insufficient input validation in the OpenofficePresentation class. When processing uploaded files, the code fails to properly sanitize the slide_width and slide_height parameters before using them in command construction. These parameters are split from user-supplied size input but are not type-casted to integers, allowing injection of shell metacharacters that can lead to command execution (STAR Labs).

Impact

Successful exploitation allows authenticated users with Learning Path upload permissions to execute arbitrary commands on the target system with the privileges of the web server user. This could lead to complete system compromise, data theft, or service disruption (STAR Labs).

Exploitability

The vulnerability requires specific conditions to be exploitable: the attacker must have permissions to upload learning paths (e.g., Trainer user role), Chamilo RAPID (Rapid Learning tool) must be enabled, and the service_ppt2lp API configuration option must be set to localhost. A proof-of-concept exploit has been publicly documented (STAR Labs).

Mitigation and workarounds

The vulnerability has been patched in version 1.11.26. The fix involves using escapeshellarg() to properly escape user input used in shell command construction. Users are strongly encouraged to upgrade to the latest version. Detection can be implemented by monitoring server access logs for suspicious requests to specific endpoints like /main/lp/lp_upload.php with non-empty ppt2lp POST parameters (STAR Labs, Chamilo Commit).

Additional resources


SourceThis report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoJul 20, 2026
CVE-2026-40291HIGH8.8
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoApr 14, 2026
CVE-2026-35196HIGH8.8
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoApr 14, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoJul 20, 2026
CVE-2026-34602HIGH7.1
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesApr 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management