Vulnerability record · CVE-2023-3368 · published 28 November 2023
CVE-2023-3368: Chamilo LMS unauthenticated command injection in additional_webservices.php
Chamilo · Chamilo
Chamilo LMS through v1.11.20 fails to neutralise special characters in /main/webservices/additional_webservices.php, allowing OS command injection. The flaw is a bypass of the earlier CVE-2023-34960 fix, so sites that patched only that issue remain exposed to remote code execution.
Description
Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE with CVSS 9.8, a public exploit reference and very high EPSS makes this an urgent patch target.
What it is
Chamilo LMS through v1.11.20 fails to neutralise special characters in /main/webservices/additional_webservices.php, allowing OS command injection. The flaw is a bypass of the earlier CVE-2023-34960 fix, so sites that patched only that issue remain exposed to remote code execution.
Impact
An unauthenticated attacker can execute arbitrary operating system commands on the server, leading to full compromise of the LMS host and any data or credentials it holds.
Attack surface
Reachable over the network via HTTP requests to the additional_webservices.php endpoint; no authentication and no user interaction are required per the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.697, 99.3rd percentile) and a third-party advisory is tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade Chamilo LMS past v1.11.20 to a release containing the patch commits referenced in the advisory.
- If immediate upgrade is not possible, block or restrict external access to /main/webservices/additional_webservices.php at the web server or WAF.
- Verify the CVE-2023-34960 fix is applied and confirm this bypass is also closed, since patching only the earlier issue is insufficient.
- Run the LMS with least privilege and restrict outbound network access from the web server to limit post-exploitation movement.
Detection
- Inspect web server and application logs for requests to /main/webservices/additional_webservices.php, especially with shell metacharacters or unexpected parameters.
- Monitor for child processes spawned by the web server user (PHP-FPM/Apache) such as sh, bash, curl or wget.
- Alert on outbound connections or file writes originating from the Chamilo web process outside normal application behaviour.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-3368 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-3368), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.