Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
CVE ID: CVE-2023-4223
CVSS Base Severity: HIGH
CVSS Base Score: 8.8
Vendor: Chamilo
Product: Chamilo
EPSS Score: 0.45% (probability of being exploited)
EPSS Percentile: 75.14% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)