CVE-2025-50187: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-50187 is an eval injection vulnerability in Chamilo LMS that allows unauthenticated remote attackers to execute arbitrary code via crafted SOAP requests. It affects Chamilo LMS versions up to and including 1.11.26, and was patched in version 1.11.28. The vulnerability was discovered by Vladimir Vlasov of Positive Technologies and publicly disclosed on March 1–2, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory).

Technical details

The root cause is CWE-95 (Improper Neutralization of Directives in Dynamically Evaluated Code — Eval Injection). The vulnerability resides in the NuSOAP library (version 0.9.5, bundled with Chamilo) at main\inc\lib\nusoap\class.soap_server.php in the invoke_method function. When the PHP function call_user_func_array is disabled via php.ini (disable_functions = call_user_func_array), the library falls back to evaluating SOAP request parameters directly without sanitization, enabling arbitrary PHP code execution. The NuSOAP library itself (up to its current version 0.9.16) remains vulnerable to this issue (GitHub Advisory).

Impact

Successful exploitation grants an unauthenticated remote attacker full code execution on the server hosting Chamilo LMS, resulting in high impact to confidentiality, integrity, and availability. An attacker can read, modify, or delete sensitive educational data (student records, credentials, course content), install backdoors or web shells, and use the compromised server as a pivot point for lateral movement within the network. No user interaction is required, making this exploitable at scale against any internet-facing Chamilo instance with the vulnerable configuration (GitHub Advisory, Feedly).

Exploitability

A proof-of-concept exploit is publicly available via the GitHub security advisory, though there is no confirmed evidence of active in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.41%, reflecting a currently low but non-negligible probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a specific precondition: call_user_func_array must be listed in disable_functions in php.ini, which limits the attack surface to misconfigured deployments (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Chamilo LMS instances running version 1.11.26 or earlier using tools like Shodan or Censys, searching for Chamilo-specific HTTP headers or login pages.
  2. Verify precondition: Confirm that the target server has call_user_func_array listed in disable_functions within php.ini — this triggers the vulnerable fallback code path in NuSOAP.
  3. Locate the SOAP endpoint: Identify the NuSOAP-based SOAP endpoint exposed by Chamilo LMS (typically accessible without authentication).
  4. Craft malicious SOAP request: Construct a SOAP request containing a payload in a parameter that will be passed to the vulnerable invoke_method function in class.soap_server.php. Embed arbitrary PHP code (e.g., a system command or reverse shell) as the parameter value.
  5. Trigger eval injection: Send the crafted SOAP request to the target endpoint. The NuSOAP library, lacking call_user_func_array, evaluates the parameter directly via eval() without sanitization, executing the injected PHP code as the web server user.
  6. Achieve persistence: Use the initial code execution to deploy a web shell, establish a reverse shell, or create a backdoor account for persistent access (GitHub Advisory).

Indicators of compromise

  • Network: Unusual or malformed SOAP requests (HTTP POST with Content-Type: text/xml or application/soap+xml) to Chamilo LMS endpoints from unexpected source IPs; outbound connections from the web server process to external IPs (potential reverse shell activity).
  • Logs: Web server access logs showing POST requests to NuSOAP-related endpoints with abnormally large or encoded XML bodies; PHP error logs referencing eval() calls or unexpected function execution in class.soap_server.php.
  • File System: Newly created PHP files (web shells) in the Chamilo web root or upload directories; unexpected modification timestamps on files in main/inc/lib/nusoap/.
  • Process: Unusual child processes spawned by the web server process (e.g., bash, sh, curl, wget, python) indicating command execution; unexpected network connections initiated by the PHP/Apache/Nginx process.

Mitigation and workarounds

The primary remediation is to upgrade Chamilo LMS to version 1.11.28, which patches this vulnerability (GitHub Release). As an immediate workaround, remove call_user_func_array from the disable_functions directive in php.ini — this eliminates the vulnerable fallback code path in NuSOAP. Additionally, restrict network access to SOAP endpoints at the firewall or web server level if SOAP functionality is not required. Escaping user input before evaluation in the NuSOAP library is also recommended as a defense-in-depth measure (GitHub Advisory).

Community reactions

The vulnerability was covered by The Hacker Wire, which published a dedicated write-up on the RCE via SOAP request parameter evaluation (The Hacker Wire). Security community aggregators including Vulners, VulDB, and CVEFeed.io indexed the vulnerability shortly after disclosure. Social media activity was observed on Bluesky and Mastodon, with CVE tracking accounts and security researchers sharing the advisory. The vulnerability was also tracked by CyberHub Blog and Infinit Security, indicating moderate community interest given the critical severity rating (CyberHub Blog).

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management