HIGH

CVE-2021-31933

CVSS v3

7.2

HIGH

EPSS Score

14.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht). A remote authenticated administrator is able to upload a file containing arbitrary PHP code into specific directories via main/inc/lib/fileUpload.lib.php directory traversal to achieve PHP code execution.

Technical details

Published
4/30/2021

Frequently asked questions

What is CVE-2021-31933?

A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht). A remote authenticated administrator is able to upload a file containing arbitrary PHP code into specific directories via main/inc/lib/fileUpload.lib.php directory traversal to achieve PHP code execution.

Is CVE-2021-31933 actively exploited?

Active exploitation of CVE-2021-31933 has not been confirmed. The EPSS score is 14.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-31933?

CVE-2021-31933 has a CVSS v3 base score of 7.2 (HIGH severity).

Is CVE-2021-31933 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.