← Vulnerability feed

Vulnerability record · CVE-2023-3368 · published 28 November 2023

CVE-2023-3368: Chamilo LMS unauthenticated command injection in additional_webservices.php

Chamilo · Chamilo

Chamilo LMS through v1.11.20 fails to neutralise special characters in /main/webservices/additional_webservices.php, allowing OS command injection. The flaw is a bypass of the earlier CVE-2023-34960 fix, so sites that patched only that issue remain exposed to remote code execution.

9.8 CVSS 3.1 Critical EPSS 70% · top 0.7% CWE-78 · OS command injection
9.8CVSS 3.1 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE with CVSS 9.8, a public exploit reference and very high EPSS makes this an urgent patch target.

What it is

Chamilo LMS through v1.11.20 fails to neutralise special characters in /main/webservices/additional_webservices.php, allowing OS command injection. The flaw is a bypass of the earlier CVE-2023-34960 fix, so sites that patched only that issue remain exposed to remote code execution.

Impact

An unauthenticated attacker can execute arbitrary operating system commands on the server, leading to full compromise of the LMS host and any data or credentials it holds.

Attack surface

Reachable over the network via HTTP requests to the additional_webservices.php endpoint; no authentication and no user interaction are required per the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.697, 99.3rd percentile) and a third-party advisory is tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade Chamilo LMS past v1.11.20 to a release containing the patch commits referenced in the advisory.
  • If immediate upgrade is not possible, block or restrict external access to /main/webservices/additional_webservices.php at the web server or WAF.
  • Verify the CVE-2023-34960 fix is applied and confirm this bypass is also closed, since patching only the earlier issue is insufficient.
  • Run the LMS with least privilege and restrict outbound network access from the web server to limit post-exploitation movement.

Detection

  • Inspect web server and application logs for requests to /main/webservices/additional_webservices.php, especially with shell metacharacters or unexpected parameters.
  • Monitor for child processes spawned by the web server user (PHP-FPM/Apache) such as sh, bash, curl or wget.
  • Alert on outbound connections or file writes originating from the Chamilo web process outside normal application behaviour.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-3368 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-3533Chamilo path traversal vulnerabilityPath traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attac…EPSS 3.5%9.8CVE-2023-3545Chamilo vulnerabilityImproper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated atta…EPSS 2.4%9.8CVE-2023-34960Chamilo wsConvertPpt SOAP command injectionChamilo versions 1.11.* up to 1.11.18 contain a command injection flaw in the wsConvertPpt component. A crafted PowerPoint name sent through a SOAP A…EPSS 99%analysed9.8CVE-2021-34187Chamilo sql injection vulnerabilitymain/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.EPSS 16%8.8CVE-2022-42029Chamilo unrestricted file upload vulnerabilityChamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with access to 'big file uploads'…EPSS 0.76%8.8CVE-2022-40407Chamilo unrestricted file upload vulnerabilityA zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file.EPSS 1.6%8.8CVE-2021-40662Chamilo cross-site request forgery vulnerabilityA Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a…EPSS 1.1%7.2CVE-2021-31933Chamilo vulnerabilityA remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and …EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2023-3368), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.