PT-2025-37377 · Chamilo · Chamilo
Published
2025-04-01
·
Updated
2026-03-02
·
CVE-2025-50198
CVSS v2.0
9.0
High
| AV:N/AC:L/Au:N/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Chamilo versions prior to 1.11.30
Description
Chamilo is a learning management system susceptible to deserialization of untrusted data. The issue resides in /plugin/vchamilo/views/import.php and is triggered through POST requests utilizing the
configuration file, course path, and home path parameters. Successful exploitation could allow a remote attacker to create objects of arbitrary classes.Recommendations
Update to version 1.11.30 or later.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chamilo