Confirms that Chamilo's file manager AJAX endpoint at /main/inc/lib/javascript/bigupload/inc/bigUpload.php is accessible and processes file uploads without authentication. Versions through 1.11.24 accept arbitrary file writes, enabling remote code execution via PHP webshell upload.
Is your app exploitable through CVE-2023-3533?
Scan your domain free