Vulnerability record · CVE-2023-4220 · published 28 November 2023
CVE-2023-4220: Chamilo LMS bigUpload.php unrestricted file upload enables RCE
Chamilo · Chamilo Lms
Chamilo LMS through v1.11.24 exposes an unrestricted file upload in /main/inc/lib/javascript/bigupload/inc/bigUpload.php. An unauthenticated attacker can upload a web shell, leading to stored cross-site scripting and remote code execution. The vendor rates the issue as critical impact and high risk.
Description
Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityUnauthenticated remote code execution with a public exploit and very high EPSS, though not yet in KEV.
What it is
Chamilo LMS through v1.11.24 exposes an unrestricted file upload in /main/inc/lib/javascript/bigupload/inc/bigUpload.php. An unauthenticated attacker can upload a web shell, leading to stored cross-site scripting and remote code execution. The vendor rates the issue as critical impact and high risk.
Impact
An attacker can execute arbitrary code on the server and run stored XSS against other users. This can lead to full compromise of the LMS host and its data.
Attack surface
Reachable over the network via the bigUpload.php endpoint with no authentication required. The CVSS vector notes user interaction is required (UI:R), though the description states unauthenticated attackers can upload directly.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.76, 99.5th percentile) and public exploit references exist from StarLabs and the vendor advisory.
What to do
- Upgrade Chamilo LMS to a version after v1.11.24 containing the patch commit 3b487a55076fb06f96809b790a35dcdd42f8ec49.
- If patching is not immediate, block or restrict access to /main/inc/lib/javascript/bigupload/inc/bigUpload.php at the web server or WAF.
- Disable or remove the big file upload component if it is not required.
- Enforce server-side file type and extension validation and store uploads outside the web root.
- Review and harden web server permissions so uploaded files cannot execute as scripts.
Detection
- Monitor web logs for POST requests to /main/inc/lib/javascript/bigupload/inc/bigUpload.php, especially from unauthenticated sessions.
- Alert on newly created files in upload directories with executable extensions such as .php, .phtml, .php5, or .phar.
- Hunt for web shell indicators in uploaded file content and unexpected outbound connections from the LMS server.
- Check for stored XSS payloads in uploaded content rendered to other users.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/chamilo/chamilo-lms/commit/3b487a55076fb06f96809b790a35dcdd42f8ec49 | Patch |
| https://starlabs.sg/advisories/23/23-4220 | ExploitThird Party Advisory |
| https://support.chamilo.org/projects/chamilo-18/wiki/security_issues#Issue-130-2023-09-04-Critical-impact-High-risk-Unau | Issue TrackingVendor Advisory |
| https://github.com/chamilo/chamilo-lms/commit/3b487a55076fb06f96809b790a35dcdd42f8ec49 | Patch |
| https://starlabs.sg/advisories/23/23-4220 | ExploitThird Party Advisory |
| https://support.chamilo.org/projects/chamilo-18/wiki/security_issues#Issue-130-2023-09-04-Critical-impact-High-risk-Unau | Issue TrackingVendor Advisory |
Track CVE-2023-4220 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-4220), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.