CVE-2023-34944
Chamilo LMS Arbitrary File Upload Leading to Code Execution.
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
An arbitrary file upload vulnerability exists in Chamilo's file upload component, allowing unauthenticated attackers to execute arbitrary code by uploading a crafted SVG file. This could compromise the confidentiality, integrity, and availability of the learning management system.