PT-2022-25370 · Chamilo · Chamilo

Alex Mackey

·

Published

2022-09-29

·

Updated

2025-05-20

·

CVE-2022-40407

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chamilo version 1.11
Description A zip slip vulnerability in the file upload function allows attackers to execute arbitrary code via a crafted Zip file.
Recommendations For Chamilo version 1.11, update to a version that fixes the zip slip vulnerability in the file upload function to prevent execution of arbitrary code via crafted Zip files.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-40407

Affected Products

Chamilo