Confirms Chamilo version is vulnerable and the wsConvertPpt SOAP endpoint is accessible. Versions through 1.11.18 pass the filename directly to exec() without sanitization, allowing unauthenticated remote code execution.
Is your app exploitable through CVE-2023-34960?
Scan your domain free