Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated attacker to modify existing files or create new files where allowed by system permissions. This only affects portals with the main/install/ directory still present and read-accessible. This vulnerability is fixed in 1.11.38.
The attack involves chaining improper file access control (CWE-552), allowing unlocking and execution of PHP code located in the main/install/ directory, which should be inaccessible after installation is complete. An unauthenticated attacker can use this technique to modify existing files or create new files in locations permitted by system permissions. The success of the attack requires the presence and accessibility of the main/install/ directory on the target server.
An unauthenticated attacker can modify existing application files or create new files on the server, which could lead to complete takeover of the application, including deployment of malicious code.
Update Chamilo LMS to version 1.11.38 or newer. Regardless of the update, it is recommended to remove or block access to the main/install/ directory after completing the system installation process.
Chamilo LMS in versions earlier than 1.11.38, only installations with the main/install/ directory accessible for reading.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XChamilo Lms
APPChamilo< 1.11.38
Related vulnerabilities
Chamilo LMS — przewidywalny token resetowania hasła (CWE-640)
OS Command Injection w Chamilo LMS — funkcja przenoszenia plików
Niezauwytoryzowany SQL injection w Chamilo LMS — przejęcie konta administratora
Stored XSS w Chamilo LMS — przejęcie kont wyżej uprzywilejowanych użytkowników
Stored XSS w Chamilo LMS umożliwiający przejęcie kont administratorów