CVE-2023-34960
Critical · CVSS 9.8Chamilo LMS — Command Injection via SOAP API (CWE-77)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-77
Description
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.
Search profile — drives PoC discovery
Symbols wsConvertPptSOAP APIConvertPptToPngwsConvertPptToPngPowerPointchamilomain/webservices/webservice_ppt2lp.php
Keywords CVE-2023-34960Chamilo command injectionwsConvertPpt exploitChamilo 1.11.18 RCEChamilo SOAP command injectionChamilo PowerPoint injection PoCChamilo webservice ppt2lpChamilo LMS remote code execution
Versions: v1.11.* up to v1.11.18
Ranked PoCs (26) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 4
- ★ 34Aituglo/CVE-2023-34960 needs reviewgh_search · Python
- ★ 23Ap0dexMe0/CVE-2023-34960 needs reviewgh_search · Python
- ★ 1
- ★ 0MzzdToT/Chamilo__CVE-2023-34960_RCE needs reviewtrickest
- ★ 0MzzdToT/HAC_Bored_Writing needs reviewtrickest
- ★ 0Pari-Malam/CVE-2023-34960 needs reviewtrickest
- ★ 0ThatNotEasy/CVE-2023-34960 needs reviewtrickest
- ★ 0YongYe-Security/CVE-2023-34960 needs reviewgh_search · Python
- ★ 0YongYe-Security/Chamilo_CVE-2023-34960-EXP needs reviewtrickest
- ★ 0dvtarsoul/ChExp needs reviewtrickest
- ★ 0dvtarsoul/dvtarsoul needs reviewtrickest
- ★ 0getdrive/PoC needs reviewtrickest
- ★ 0h00die-gr3y/Metasploit needs reviewtrickest
- ★ 0trickest
- ★ 0iluaster/getdrive_PoC needs reviewtrickest
- ★ 0izj007/wechat needs reviewtrickest
- ★ 0laohuan12138/exp-collect needs reviewtrickest
- ★ 0lions2012/Penetration_Testing_POC needs reviewtrickest
- ★ 0peiqiF4ck/WebFrameworkTools-5.1-main needs reviewtrickest
- ★ 0peiqiF4ck/WebFrameworkTools-5.5 needs reviewtrickest
- ★ 0peiqiF4ck/WebFrameworkTools-5.5-enhance needs reviewtrickest
- ★ 0
- ★ 0tucommenceapousser/CVE-2023-34960-ex needs reviewtrickest
- ★ 0whoami13apt/files2 needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- http://packetstormsecurity.com/files/174314/Chamilo-1.11.18-Command-Injection.html
- https://support.chamilo.org/projects/1/wiki/Security_issues#Issue-112-2023-04-20-Critical-impact-High-risk-Remote-Code-Execution
- http://chamilo.com
- http://packetstormsecurity.com/files/174314/Chamilo-1.11.18-Command-Injection.html
- https://support.chamilo.org/projects/1/wiki/Security_issues#Issue-112-2023-04-20-Critical-impact-High-risk-Remote-Code-Execution
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T18:30:39.000Z