PT-2026-31999 · Unknown · Chamilo Lms

Published

2026-04-10

·

Updated

2026-04-10

·

CVE-2026-31939

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chamilo LMS versions prior to 1.11.38
Description Chamilo LMS contains a path traversal flaw in the 'main/exercise/savescores.php' component. The issue stems from directly concatenating user-supplied input from the test parameter within the $ REQUEST array into a filesystem path without proper sanitization or traversal checks. This allows for arbitrary file deletion.
Recommendations Update to version 1.11.38 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-31939

Affected Products

Chamilo Lms