Proof of concept exploit for CVE-2023-4220# Proof of concept exploit for CVE-2023-4220
- *Affected product*: Chamilo <= 1.11.24
This CVE abuses an unathenticated file upload vulnerability in Chamilo 1.11.24 and lower.
An attacker has the ability to upload PHP files with no restrictions, leading to RCE.
## How to use
```bash
python3 exploit.py -u URL -c COMMAND
```
## Showcase
<img style="align: center" src="cve-2023-4220.gif"/>
[4.0K] /data/pocs/6f46c44c1eee3dc29c73129129077ca945f1c6d6
├── [243K] cve-2023-4220.gif
├── [1.6K] exploit.py
├── [ 34K] LICENSE
└── [ 396] README.md
0 directories, 4 files