PT-2026-23634 · Chamilo · Chamilo Lms

Meng Hokseng

·

Publicado

2026-03-06

·

Atualizado

2026-03-11

·

CVE-2026-29041

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chamilo versions prior to 1.11.34
Description Chamilo LMS is susceptible to an authenticated remote code execution issue stemming from insufficient validation of uploaded files. The application depends on MIME-type verification for file uploads, lacking adequate file extension validation and secure server-side storage restrictions. This allows a user with limited privileges to upload a malicious file containing executable code and execute arbitrary commands on the server.
Recommendations Update to version 1.11.34 or later.

Exploit

Correção

RCE

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-29041
GHSA-4PC3-4W2V-VWX8

Produtos afetados

Chamilo Lms