PT-2026-25799 · Chamilo · Chamilo Lms

Dhiyaneshgeek

+1

·

Publicado

2026-03-16

·

Atualizado

2026-03-17

·

CVE-2026-30875

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chamilo LMS versions prior to 1.11.36
Description Chamilo LMS is a learning management system. A flaw exists in the H5P Import feature that allows authenticated users with the Teacher role to achieve Remote Code Execution (RCE). The system’s validation of H5P packages only confirms the presence of the h5p.json file, failing to block potentially harmful files like .htaccess or PHP files with alternative extensions. An attacker can upload a specially crafted H5P package containing a webshell and a .htaccess file. The .htaccess file enables PHP execution for .txt files, effectively bypassing security controls. The API endpoint involved is the H5P Import feature. The vulnerable component is the H5P package validation process, specifically the function that checks for the h5p.json file. The attacker manipulates the h5p.json file and associated files within the H5P package.
Recommendations Update Chamilo LMS to version 1.11.36 or later.

Exploit

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-30875
GHSA-MJ4F-8FW2-HRFM

Produtos afetados

Chamilo Lms