CVE-2021-31933 is a remote code execution vulnerability affecting Chamilo through version 1.11.14. It stems from insufficient input sanitization during file uploads and improper filtering of file extensions like .phar or .pht. An authenticated administrator can exploit this by uploading malicious PHP code via directory traversal, leading to arbitrary code execution on the server. The vulnerability has a CVSS score of 7.2 (HIGH), indicating a high-impact threat with complete confidentiality, integrity, and availability compromise. Its attack vector is network-based with low attack complexity, requiring high privileges for exploitation. While not listed on CISA's KEV catalog, an exploit is publicly available on ExploitDB. Despite this, there is no evidence of active exploitation, and community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.11.14CPE matchmatch criteria | cpe:2.3:a:chamilo:chamilo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.