Vulnerability record · CVE-2023-34960 · published 1 August 2023
CVE-2023-34960: Chamilo wsConvertPpt SOAP command injection
Chamilo · Chamilo
Chamilo versions 1.11.* up to 1.11.18 contain a command injection flaw in the wsConvertPpt component. A crafted PowerPoint name sent through a SOAP API call is passed to a system command, allowing arbitrary command execution. The vendor rates it critical impact and high risk remote code execution.
Description
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, combined with an EPSS score above the 99th percentile, makes this an urgent remote code execution risk.
What it is
Chamilo versions 1.11.* up to 1.11.18 contain a command injection flaw in the wsConvertPpt component. A crafted PowerPoint name sent through a SOAP API call is passed to a system command, allowing arbitrary command execution. The vendor rates it critical impact and high risk remote code execution.
Impact
An unauthenticated attacker can execute arbitrary operating system commands on the Chamilo server, leading to full compromise of confidentiality, integrity and availability.
Attack surface
Reachable over the network through the SOAP API endpoint that handles PowerPoint conversion. The CVSS vector shows no privileges required and no user interaction, so the call can be made directly by an unauthenticated remote client.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is 0.99325 (99.9th percentile), indicating very high predicted exploitation activity. Public proof-of-concept material is referenced on Packet Storm.
What to do
- Upgrade Chamilo to a version later than 1.11.18 that contains the vendor fix for Issue-112.
- If immediate upgrade is not possible, restrict network access to the SOAP API and the wsConvertPpt endpoint to trusted hosts only.
- Disable or remove the PowerPoint conversion feature if it is not required.
- Apply input validation or sanitization to the PowerPoint name parameter before it reaches any shell command.
- Monitor vendor advisory and security issue tracker for updated guidance.
Detection
- Inspect SOAP API request logs for wsConvertPpt calls containing shell metacharacters or unusual characters in the PowerPoint name parameter.
- Monitor web server and application logs for command execution errors or unexpected child processes spawned by the Chamilo web user.
- Alert on outbound network connections or file writes originating from the Chamilo server process that are not part of normal application behavior.
- Use endpoint detection to flag shell command invocations whose parent process is the Chamilo web server or PHP process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-34960 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-34960), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.