Aller au contenu principal
HIGH

CVE-2024-47886

CVSS v3

7.2

HIGH

Score EPSS

1.2 %

probabilité d’exploitation

CISA KEV

Non

exploitation connue

Exploitation

statut SSVC

Description

Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a remote code execution (RCE) within versions 1.11.12 to 1.11.26. By abusing multiple supported features from the virtualization plugin vchamilo, the vulnerability allows an administrator to execute arbitrary code on the server. This issue has been patched in version 1.11.26.

Détails techniques

Vecteur CVSS v3
3.1
Publiée le
2026-03-02
Dernière modification
2026-03-03

Questions fréquentes

Qu’est-ce que CVE-2024-47886 ?

Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a remote code execution (RCE) within versions 1.11.12 to 1.11.26. By abusing multiple supported features from the virtualization plugin vchamilo, the vulnerability allows an administrator to execute arbitrary code on the server. This issue has been patched in version 1.11.26.

CVE-2024-47886 est-elle activement exploitée ?

Aucune exploitation active de CVE-2024-47886 n’est confirmée. Le score EPSS est de 1.2 %, soit la probabilité estimée d’exploitation dans les 30 prochains jours.

Quel est le score CVSS de CVE-2024-47886 ?

CVE-2024-47886 a un score de base CVSS v3 de 7.2 (gravité HIGH), avec le vecteur 3.1.

CVE-2024-47886 touche-t-elle votre environnement ?

Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.

Sans carte bancaire · 500 vérifications gratuites par mois · Clé API gratuite