CVE-2023-34960
chamilo
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.
- CVSS
- 9.8
- EPSS
- 99.2% 99.9% percentile
- CISA KEV
- Not listed
- Published
- 2023.08.01