PT-2026-32013 · Unknown · Chamilo Lms
Published
2026-04-10
·
Updated
2026-04-11
·
CVE-2026-33618
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Chamilo LMS versions prior to 2.0.0-RC.3
Description
Chamilo LMS, a learning management system, has an issue where the
PlatformConfigurationController::decodeSettingArray() method uses PHP's eval() function to process platform settings retrieved from the database. An attacker with administrator privileges can inject arbitrary PHP code into these settings. This injected code is then executed when any user, even unauthenticated ones, accesses the '/platform-config/list' API endpoint. This allows for remote code execution.Recommendations
Upgrade to version 2.0.0-RC.3 or later.
Fix
RCE
Eval Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chamilo Lms