PT-2025-37377 · Chamilo · Chamilo

Published

2025-04-01

·

Updated

2026-03-02

·

CVE-2025-50198

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions Chamilo versions prior to 1.11.30
Description Chamilo is a learning management system susceptible to deserialization of untrusted data. The issue resides in /plugin/vchamilo/views/import.php and is triggered through POST requests utilizing the configuration file, course path, and home path parameters. Successful exploitation could allow a remote attacker to create objects of arbitrary classes.
Recommendations Update to version 1.11.30 or later.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06911
CVE-2025-50198
GHSA-JGXC-96J5-8RRR

Affected Products

Chamilo