PT-2025-37377 · Chamilo · Chamilo

Published

2025-04-01

·

Updated

2026-03-02

·

CVE-2025-50198

CVSS v2.0

9.0

High

AV:N/AC:L/Au:N/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions Chamilo versions prior to 1.11.30
Description Chamilo is a learning management system susceptible to deserialization of untrusted data. The issue resides in /plugin/vchamilo/views/import.php and is triggered through POST requests utilizing the configuration file, course path, and home path parameters. Successful exploitation could allow a remote attacker to create objects of arbitrary classes.
Recommendations Update to version 1.11.30 or later.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2025-06911
CVE-2025-50198
GHSA-JGXC-96J5-8RRR

Affected Products

Chamilo