← Vulnerability feed

Vulnerability record · CVE-2023-34960 · published 1 August 2023

CVE-2023-34960: Chamilo wsConvertPpt SOAP command injection

Chamilo · Chamilo

Chamilo versions 1.11.* up to 1.11.18 contain a command injection flaw in the wsConvertPpt component. A crafted PowerPoint name sent through a SOAP API call is passed to a system command, allowing arbitrary command execution. The vendor rates it critical impact and high risk remote code execution.

9.8 CVSS 3.1 Critical EPSS 99% · top 0.1% CWE-77 · Command injection
9.8CVSS 3.1 base score
99%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
9 Jul 2026Last modified by NVD

Description

A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, combined with an EPSS score above the 99th percentile, makes this an urgent remote code execution risk.

What it is

Chamilo versions 1.11.* up to 1.11.18 contain a command injection flaw in the wsConvertPpt component. A crafted PowerPoint name sent through a SOAP API call is passed to a system command, allowing arbitrary command execution. The vendor rates it critical impact and high risk remote code execution.

Impact

An unauthenticated attacker can execute arbitrary operating system commands on the Chamilo server, leading to full compromise of confidentiality, integrity and availability.

Attack surface

Reachable over the network through the SOAP API endpoint that handles PowerPoint conversion. The CVSS vector shows no privileges required and no user interaction, so the call can be made directly by an unauthenticated remote client.

Exploitation

Not listed in CISA KEV and no ransomware association is documented, but EPSS is 0.99325 (99.9th percentile), indicating very high predicted exploitation activity. Public proof-of-concept material is referenced on Packet Storm.

What to do

  • Upgrade Chamilo to a version later than 1.11.18 that contains the vendor fix for Issue-112.
  • If immediate upgrade is not possible, restrict network access to the SOAP API and the wsConvertPpt endpoint to trusted hosts only.
  • Disable or remove the PowerPoint conversion feature if it is not required.
  • Apply input validation or sanitization to the PowerPoint name parameter before it reaches any shell command.
  • Monitor vendor advisory and security issue tracker for updated guidance.

Detection

  • Inspect SOAP API request logs for wsConvertPpt calls containing shell metacharacters or unusual characters in the PowerPoint name parameter.
  • Monitor web server and application logs for command execution errors or unexpected child processes spawned by the Chamilo web user.
  • Alert on outbound network connections or file writes originating from the Chamilo server process that are not part of normal application behavior.
  • Use endpoint detection to flag shell command invocations whose parent process is the Chamilo web server or PHP process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-34960 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-3533Chamilo path traversal vulnerabilityPath traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attac…EPSS 3.5%9.8CVE-2023-3545Chamilo vulnerabilityImproper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated atta…EPSS 2.4%9.8CVE-2023-3368Chamilo LMS unauthenticated command injection in additional_webservices.phpChamilo LMS through v1.11.20 fails to neutralise special characters in /main/webservices/additional_webservices.php, allowing OS command injection. T…EPSS 70%analysed9.8CVE-2021-34187Chamilo sql injection vulnerabilitymain/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.EPSS 16%8.8CVE-2022-42029Chamilo unrestricted file upload vulnerabilityChamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with access to 'big file uploads'…EPSS 0.76%8.8CVE-2022-40407Chamilo unrestricted file upload vulnerabilityA zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file.EPSS 1.6%8.8CVE-2021-40662Chamilo cross-site request forgery vulnerabilityA Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a…EPSS 1.1%7.2CVE-2021-31933Chamilo vulnerabilityA remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and …EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2023-34960), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.