CVE-2023-4221: Chamilo Lms
High severity, CVSS 8.8. EPSS: 3.5% chance of exploitation in the next 30 days.
Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
Affected products
- Chamilo Chamilo Lms: up to and including 1.11.24
Published 2023-11-28. Last modified 2026-06-17.