Skip to content

CVE-2023-34960 | Fix and communication #4751

@meuhland

Description

@meuhland

Being a heavy user of Chamilo with a portal that includes a lot of modification the disclosure of this CVE issue is a bit problematic.

The proof of concept by the researcher has been published over a week ago, the issue could have been mitigated before attack have been spotted in the wild.

For those of you running portal in a similar situation the fix seems to be related to this commit
7ecc0c9

I do agree that making this might not be in the best interest of the Chamilo project but the PoC and the attacks are out there and giving people running customized portals a way to at the very least be safe should be a priority.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions