Loading
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.
Use CWE-77, Chamilo vendor hub and Chamilo product page to widen CVE-2023-34960 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-3545, CVE-2023-3533 and CVE-2023-3368 for nearby disclosures in the same product family.