CVE-2025-50186: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-50186 is a stored cross-site scripting (XSS) vulnerability in Chamilo LMS affecting versions up to and including 1.11.28. The flaw arises from insufficient sanitization of CSV filenames during the user import process, allowing an attacker to upload a maliciously named file (e.g., <img src=q onerror=prompt(8)>.csv) that executes JavaScript when viewed by administrators or other privileged users. It was disclosed on March 2, 2026, and patched in version 1.11.30. The vulnerability carries a CVSS v3.1 base score of 4.8 (Medium) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), classified as a stored XSS. The vulnerable endpoint is /main/admin/user_import.php, which stores the raw, unsanitized filename of uploaded CSV files; the stored filename is later rendered without encoding in pages such as /main/admin/download_import_users.php. The fix, applied in commit 9fef8f3, introduces api_replace_dangerous_char() and disable_dangerous_file() calls to sanitize the filename before storage. Exploitation requires the attacker to have (or trick someone with) file upload privileges, and a victim with access to import logs or file views must subsequently load the affected page (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows arbitrary JavaScript to execute in the browser context of any authenticated user — particularly administrators — who views the import logs or file management pages. This can lead to full session hijacking, admin account compromise, persistent in-browser attacks, and tampering with platform settings or user data. Because the payload is stored server-side, it persists and can affect multiple victims over time without further attacker interaction (GitHub Advisory).

Exploitability

A proof-of-concept is publicly referenced in the GitHub security advisory, but there is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.03%, reflecting low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high privileges (upload access) and user interaction (an admin viewing the affected page), which limits the attack surface (GitHub Advisory, Red Hat CVE).

Exploitation steps

  1. Identify target: Locate a Chamilo LMS instance running version ≤ 1.11.28 with the user import feature accessible.
  2. Obtain upload access: Either authenticate with an account that has CSV import privileges (admin, HR manager, or course manager), or socially engineer a privileged user into uploading a prepared file.
  3. Craft malicious filename: Create a CSV file with a filename containing an XSS payload, e.g., <img src=q onerror=alert(document.cookie)>.csv. The file contents can be a valid CSV to avoid suspicion.
  4. Upload the file: Navigate to /main/admin/user_import.php and upload the maliciously named CSV file through the user import form.
  5. Trigger execution: The payload fires immediately upon upload confirmation, or later when any administrator or authorized user visits /main/admin/download_import_users.php or any page that renders the stored filename.
  6. Harvest session data: The executed JavaScript can exfiltrate session cookies, perform actions on behalf of the victim, or establish persistent access to the admin interface (GitHub Advisory).

Indicators of compromise

  • Network: HTTP POST requests to /main/admin/user_import.php with a Content-Disposition filename containing HTML tags (e.g., <img, <script, onerror=, onload=); outbound requests from admin browsers to unexpected external hosts following access to import log pages.
  • File System: Presence of files in app/cache/backup/import_users/ with filenames containing HTML or JavaScript characters (e.g., <, >, onerror).
  • Logs: Web server access logs showing uploads to user_import.php with URL-encoded HTML entities in the filename field; subsequent access to download_import_users.php by admin accounts shortly after a suspicious upload.
  • Process/Browser: Unexpected JavaScript execution or network requests originating from admin browser sessions after viewing import history pages (GitHub Advisory).

Mitigation and workarounds

The primary remediation is to upgrade Chamilo LMS to version 1.11.30 or later, which sanitizes uploaded CSV filenames using api_replace_dangerous_char() and disable_dangerous_file() before storage (Patch Commit, Release Notes). As interim mitigations, restrict CSV upload access to the minimum necessary trusted users, implement Content Security Policy (CSP) headers to reduce XSS impact, and monitor import logs for filenames containing HTML or JavaScript characters. Reviewing audit logs for suspicious CSV upload activity is also recommended.

Community reactions

The vulnerability was reported by researcher NaklehZeidan21 and remediated by developer AngelFQC, as credited in the official GitHub security advisory. A technical write-up was published by Infinit Security shortly after disclosure, detailing the exploitation path via user_import.php. No major vendor statements beyond the GitHub advisory or significant broader media coverage have been identified (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management