All verified exploits

CVE-2023-4220 Unauthenticated File Upload RCE

Deterministic critical Chamilo Added cve-verified-cve-2023-4220

Confirms that Chamilo's Big File Upload endpoint at /main/inc/lib/javascript/bigupload/inc/bigUpload.php is accessible without authentication and accepts arbitrary file types. Versions through 1.11.24 allow direct PHP webshell upload and execution.

Is your app exploitable through CVE-2023-4220?

Scan your domain free