← Vulnerability feed

Vulnerability record · CVE-2023-4220 · published 28 November 2023

CVE-2023-4220: Chamilo LMS bigUpload.php unrestricted file upload enables RCE

Chamilo · Chamilo Lms

Chamilo LMS through v1.11.24 exposes an unrestricted file upload in /main/inc/lib/javascript/bigupload/inc/bigUpload.php. An unauthenticated attacker can upload a web shell, leading to stored cross-site scripting and remote code execution. The vendor rates the issue as critical impact and high risk.

6.1 CVSS 3.1 Medium EPSS 76% · top 0.5% CWE-434 · Unrestricted file uploadCWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated remote code execution with a public exploit and very high EPSS, though not yet in KEV.

What it is

Chamilo LMS through v1.11.24 exposes an unrestricted file upload in /main/inc/lib/javascript/bigupload/inc/bigUpload.php. An unauthenticated attacker can upload a web shell, leading to stored cross-site scripting and remote code execution. The vendor rates the issue as critical impact and high risk.

Impact

An attacker can execute arbitrary code on the server and run stored XSS against other users. This can lead to full compromise of the LMS host and its data.

Attack surface

Reachable over the network via the bigUpload.php endpoint with no authentication required. The CVSS vector notes user interaction is required (UI:R), though the description states unauthenticated attackers can upload directly.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.76, 99.5th percentile) and public exploit references exist from StarLabs and the vendor advisory.

What to do

  • Upgrade Chamilo LMS to a version after v1.11.24 containing the patch commit 3b487a55076fb06f96809b790a35dcdd42f8ec49.
  • If patching is not immediate, block or restrict access to /main/inc/lib/javascript/bigupload/inc/bigUpload.php at the web server or WAF.
  • Disable or remove the big file upload component if it is not required.
  • Enforce server-side file type and extension validation and store uploads outside the web root.
  • Review and harden web server permissions so uploaded files cannot execute as scripts.

Detection

  • Monitor web logs for POST requests to /main/inc/lib/javascript/bigupload/inc/bigUpload.php, especially from unauthenticated sessions.
  • Alert on newly created files in upload directories with executable extensions such as .php, .phtml, .php5, or .phar.
  • Hunt for web shell indicators in uploaded file content and unexpected outbound connections from the LMS server.
  • Check for stored XSS payloads in uploaded content rendered to other users.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-4220 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-33707Chamilo lms weak password recovery vulnerabilityChamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email…EPSS 0.75%9.8CVE-2025-50187Chamilo lms vulnerabilityChamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filtering which leads to Remote C…EPSS 0.90%9.8CVE-2023-34944Chamilo lms unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary co…EPSS 1.1%9.8CVE-2022-27423Chamilo lms sql injection vulnerabilityChamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php.EPSS 0.99%9.8CVE-2021-35414Chamilo lms sql injection vulnerabilityChamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php.EPSS 1.9%9.8CVE-2019-13082Chamilo lms unrestricted file upload vulnerabilityChamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive befor…EPSS 4.0%9.8CVE-2018-1999019Chamilo lms code injection vulnerabilityChamilo LMS version 11.x contains an Unserialization vulnerability in the "hash" GET parameter for the api endpoint located at /webservices/api/v2.ph…EPSS 3.2%9.3CVE-2026-33698Chamilo lms vulnerabilityChamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ director…EPSS 0.58%

Source: NIST National Vulnerability Database (record CVE-2023-4220), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.