PT-2026-23634 · Chamilo · Chamilo Lms

Meng Hokseng

·

Published

2026-03-06

·

Updated

2026-03-11

·

CVE-2026-29041

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chamilo versions prior to 1.11.34
Description Chamilo LMS is susceptible to an authenticated remote code execution issue stemming from insufficient validation of uploaded files. The application depends on MIME-type verification for file uploads, lacking adequate file extension validation and secure server-side storage restrictions. This allows a user with limited privileges to upload a malicious file containing executable code and execute arbitrary commands on the server.
Recommendations Update to version 1.11.34 or later.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-29041
GHSA-4PC3-4W2V-VWX8

Affected Products

Chamilo Lms