CVE-2023-4220: Chamilo Lms

Medium severity, CVSS 6.1. EPSS: 76.1% chance of exploitation in the next 30 days.

Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.

Affected products

  • Chamilo Chamilo Lms: up to and including 1.11.24

Published 2023-11-28. Last modified 2026-06-17.