Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-4220
HistoryNov 28, 2023 - 8:15 a.m.

Cross site scripting

2023-11-2808:15:00
PRIOn knowledge base
www.prio-n.com
2
cross site scripting
unauthenticated attackers
stored attacks
remote code execution
file upload vulnerability
big file upload functionality
chamilo lms security bug

7.5 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

53.2%

Unrestricted file upload in big file upload functionality in /main/inc/lib/javascript/bigupload/inc/bigUpload.php in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.

CPENameOperatorVersion
chamilo_lmsle1.11.24

7.5 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

53.2%

Related for PRION:CVE-2023-4220