Confirms that Chamilo's Big File Upload endpoint at /main/inc/lib/javascript/bigupload/inc/bigUpload.php is accessible without authentication and accepts arbitrary file types. Versions through 1.11.24 allow direct PHP webshell upload and execution.
Is your app exploitable through CVE-2023-4220?
Scan your domain free