CVE-2023-3368: Chamilo

Critical severity, CVSS 9.8. EPSS: 69.7% chance of exploitation in the next 30 days.

Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960.

Affected products

  • Chamilo Chamilo: before 1.11.20 (fixed in 1.11.20)

Published 2023-11-28. Last modified 2026-06-17.