PT-2025-37308 · Chamilo · Chamilo

Published

2025-04-01

·

Updated

2026-03-07

·

CVE-2025-50193

CVSS v2.0

8.7

High

AV:N/AC:L/Au:S/C:P/I:C/A:C
Name of the Vulnerable Software and Affected Versions Chamilo versions prior to 1.11.30
Description Chamilo is a learning management system with a command injection issue. Exploitation may allow a remote attacker to execute arbitrary SQL queries. The issue is located in the /plugin/vchamilo/views/import.php file, specifically with the to main database parameter when receiving POST requests.
Recommendations Update to version 1.11.30 or later.

Exploit

Fix

Command Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-06906
CVE-2025-50193
GHSA-HVPP-6MP9-FRX4

Affected Products

Chamilo