PT-2025-35788 · Unknown · Chamilo Lms

Published

2025-04-01

·

Updated

2026-03-07

·

CVE-2025-50189

CVSS v3.1

8.8

High

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chamilo LMS versions prior to 1.11.30
Description The Chamilo LMS system has an issue due to inadequate validation of XML object sequences. Successful exploitation could allow a remote attacker to execute arbitrary SQL queries. The application does not sufficiently validate data received from the user via the document POST resource and login POST parameters in the '/main/coursecopy/copy course session selected.php' file, enabling an attacker to modify database query logic by injecting arbitrary SQL statements. The vulnerable parameter is SQL INJECTION HERE.
Recommendations Update to version 1.11.30 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-06902
CVE-2025-50189
GHSA-VXX3-648J-7P4R

Affected Products

Chamilo Lms