CVE-2025-50188: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-50188 is an error-based SQL injection vulnerability in the vchamilo plugin of Chamilo LMS, a widely used open-source learning management system. The flaw affects all versions prior to 1.11.30 (specifically confirmed through 1.11.28) and was discovered by Aleksey Solovev of Positive Technologies, with the advisory published on March 1–2, 2026. It carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 7.0 (High) (GitHub Advisory).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and stems from insufficient validation of user-supplied data passed via the GET value parameter in two scripts: /plugin/vchamilo/views/syncparams.php and /plugin/vchamilo/ajax/service.php. The affected code directly concatenated unsanitized GET parameters into SQL queries (e.g., DELETE, UPDATE, and SELECT statements) without using parameterized queries or prepared statements, allowing an attacker to manipulate the query logic. Exploitation requires the attacker to be authenticated with administrator-level privileges, and no user interaction is needed beyond the attacker's own actions (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows a privileged attacker to read sensitive data from the database (high confidentiality impact), disrupt database availability through malicious queries (high availability impact), and potentially modify or delete database records. While the CVSS v4.0 score reflects no integrity impact on the vulnerable system, the CVSS v3.1 score assigns high integrity impact, indicating the potential for unauthorized data modification. The attack is conducted entirely over the network without requiring user interaction, making it straightforward for any administrator-level account that has been compromised or is acting maliciously (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly referenced via the GitHub security advisory, though there is no evidence of active in-the-wild exploitation at this time. The vulnerability requires high privileges (administrator role), which limits the attack surface compared to unauthenticated vulnerabilities. The EPSS score is approximately 0.041%, reflecting a low probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify Chamilo LMS instances running versions prior to 1.11.30 (≤1.11.28) with the vchamilo plugin enabled, using web fingerprinting tools or by checking publicly accessible login pages.
  2. Obtain administrator credentials: Acquire valid administrator-level credentials through phishing, credential stuffing, or other means, as exploitation requires the administrator role.
  3. Authenticate: Log in to the Chamilo LMS admin panel using the obtained credentials.
  4. Craft malicious GET request: Send a crafted HTTP GET request to one of the vulnerable endpoints (e.g., /plugin/vchamilo/views/syncparams.php or /plugin/vchamilo/ajax/service.php) with a malicious SQL payload injected into the value parameter (e.g., ?what=syncthis&settingid=1&value=' OR 1=1--).
  5. Extract or manipulate data: Use error-based SQL injection techniques to enumerate database structure, extract sensitive data (user credentials, course data), or execute destructive queries against the database (GitHub Advisory, Patch Commit).

Indicators of compromise

  • Network: Unusual or repeated HTTP GET requests to /plugin/vchamilo/views/syncparams.php or /plugin/vchamilo/ajax/service.php containing SQL metacharacters (e.g., single quotes, OR, UNION, --, SELECT) in the value or settingid parameters.
  • Logs: Web server access logs showing requests to the vchamilo plugin endpoints with anomalous parameter values; database error messages in application logs indicating malformed SQL queries (error-based injection artifacts).
  • Database: Unexpected changes to the settings_current table, including unauthorized modifications to configuration values or deletions of records; unusual database queries originating from the web application user account.
  • Application: Unexpected changes to Chamilo platform settings or configuration values that do not correspond to legitimate administrator activity (GitHub Advisory).

Mitigation and workarounds

The primary remediation is to upgrade Chamilo LMS to version 1.11.30, which replaces direct SQL string concatenation with parameterized queries (prepared statements) and uses the Doctrine DBAL delete(), update(), and insert() methods for safe database operations (Patch Commit, Release Notes). As a temporary workaround, administrators should restrict network-level access to the affected endpoints (/plugin/vchamilo/views/syncparams.php and /plugin/vchamilo/ajax/service.php) to trusted IP addresses only, and enforce the principle of least privilege for administrator accounts. Additionally, monitoring database logs for suspicious SQL activity and reviewing access logs for the affected endpoints is recommended (GitHub Advisory).

Community reactions

The vulnerability was discovered and reported by Aleksey Solovev of Positive Technologies, a well-known security research firm. The advisory was published by the Chamilo project maintainers on GitHub and tracked by Red Hat's security advisory database. No significant broader media coverage or notable social media discussion beyond standard CVE tracking feeds has been observed for this vulnerability.

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management