CVE-2023-3545
Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `.htaccess` file. This vulnerability may be exploited by privileged attackers or chained with unauthenticated arbitrary file write vulnerabilities, such as CVE-2023-3533, to achieve remote code execution.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 2.99%
- CWE
- CWE-178
- Published
- 2023-11-28
- Last modified
- 2026-03-13
Affected products
- Chamilo Chamilo
Weakness type
Related vulnerabilities
- CVE-2023-4759 — Improper handling of case insensitive filesystems in Eclipse JGit allows arbitrary file write
- CVE-2025-46701 — Apache Tomcat: Security constraint bypass for CGI scripts
- CVE-2026-43513 — Apache Tomcat: LockOutRealm treats user names as case-sensitive
- CVE-2025-67718 — Formio improperly authorized permission elevation through specially crafted request path
- CVE-2026-40453 — Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, camel-coap, camel-google-pubsub) allows case-variant header injection
- CVE-2021-39155 — Authorization Policy Bypass Due to Case Insensitive Host Comparison
- CVE-2026-47323 — Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering
- CVE-2026-28292 — simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key that enables RCE