S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-34960 Scanner

Detects 'OS Command Injection' vulnerability in Chamilo affects v. 1.11.* up to v1.11.18.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-34960
9.8
CVSS

A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Chamilo is an open-source e-learning platform used by educational institutions, businesses, and governments around the world. Its main purpose is to provide an online learning environment where teachers and students can interact, share course materials and assignments, take quizzes, and track their progress. With its user-friendly interface and customizable features, Chamilo has become a popular choice for educators who want to deliver high-quality education to their students.

The CVE-2023-34960 vulnerability detected in Chamilo v1.11.* up to v1.11.18 is a command injection vulnerability in the wsConvertPpt component. This vulnerability can be exploited by attackers who send a SOAP API call with a crafted PowerPoint name. The input validation of the application fails to correctly sanitize the input, which allows an attacker to inject arbitrary commands that could lead to remote code execution. 

If this vulnerability is exploited, attackers can run arbitrary commands on the system and gain unauthorized access to sensitive data, modify or delete critical files, and take control of the entire system. This can lead to data breaches, financial loss, reputational damage, and legal liability. 

Thanks to the pro features of the s4e.io platform, readers of this article can easily and quickly learn about vulnerabilities in their digital assets. This platform offers a comprehensive vulnerability scanning, penetration testing, and compliance assessment service, which helps organizations identify and mitigate security risks efficiently. With s4e.io, users can protect their networks, applications, and data from cyber threats and security breaches.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Keep the Chamilo software up to date by applying the latest security patches and updates.
  • Implement firewall rules to block unauthorized access to the affected component.
  • Use strong passwords for all user accounts and apply two-factor authentication where possible.
  • Perform regular vulnerability scans and penetration tests to identify and remediate security issues proactively.
  • Educate users on the importance of cybersecurity hygiene and encourage them to report any suspicious activities immediately.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-34960 scanner - OS Command Injection vulnerability in Chamilo S4E