CVE-2025-50189: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-50189 is an error-based SQL injection vulnerability in Chamilo LMS, an open-source learning management system. The flaw exists in /main/coursecopy/copy_course_session_selected.php, where insufficient validation of the POST resource[document][SQL_INJECTION_HERE] and login parameters allows authenticated attackers to inject arbitrary SQL statements and manipulate database query logic. All Chamilo LMS versions prior to 1.11.30 (specifically ≤1.11.28) are affected. The vulnerability was published on March 2, 2026, and patched in version 1.11.30. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 7.2 (High) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), arising from direct string concatenation of user-supplied POST parameters into SQL queries within the CourseSelectForm::get_posted_course() method in src/Chamilo/CourseBundle/Component/CourseCopy/CourseSelectForm.php. The vulnerable code used raw Database::query($sql) calls where the $resource_item variable — derived from the POST resource[document] array keys — was inserted directly into the SQL string without sanitization or parameterization. An attacker with at least a trainer-level (low-privilege) authenticated session can craft a malicious POST request to /main/coursecopy/copy_course_session_selected.php with injected SQL in the document resource key or login parameter. The fix replaced raw query construction with parameterized Database::select() calls using prepared statement-style ? placeholders (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an authenticated low-privileged attacker to read sensitive data from the database (high confidentiality impact), potentially including user credentials, course content, and personal information of students and instructors. The attacker can also manipulate or delete database records (high integrity impact) and cause denial of service through destructive SQL operations (high availability impact). The attack requires only network access and a minimal trainer-level account, with no user interaction needed, making it accessible to any enrolled or registered user on the platform (GitHub Advisory).

Exploitability

A proof-of-concept reference is available via the GitHub Security Advisory, and a technical write-up was published at infinitsec.net shortly after disclosure. The EPSS score is approximately 0.05%, indicating low current exploitation probability. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid authenticated session with at minimum a trainer role, limiting the attack surface compared to unauthenticated vulnerabilities (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify Chamilo LMS instances running versions ≤1.11.28 using web fingerprinting tools (e.g., Wappalyzer, Shodan) or by checking the Chamilo version page.
  2. Obtain credentials: Acquire a low-privileged account with at least the trainer role — this may be a free self-registration, a phished account, or a brute-forced credential.
  3. Authenticate: Log in to the Chamilo instance to obtain a valid session cookie.
  4. Craft malicious POST request: Send a POST request to /main/coursecopy/copy_course_session_selected.php with a crafted resource[document] array key containing an SQL injection payload (e.g., resource[document][1 AND EXTRACTVALUE(1,CONCAT(0x7e,(SELECT version())))]) or inject into the login POST parameter.
  5. Extract data via error-based injection: Observe database error messages returned in the HTTP response that leak database content (e.g., database version, table names, user credentials) through the injected EXTRACTVALUE or similar error-based SQL functions.
  6. Enumerate and exfiltrate: Iterate through tables and columns to extract sensitive data such as user password hashes, email addresses, and course records (GitHub Advisory).

Indicators of compromise

  • Network: Unusual POST requests to /main/coursecopy/copy_course_session_selected.php containing SQL keywords (e.g., SELECT, UNION, EXTRACTVALUE, CONCAT, 0x) in the resource[document] parameter keys or login parameter.
  • Logs: Web server access logs showing POST requests to the course copy endpoint with abnormally long or encoded parameter names; application error logs containing MySQL/database error messages referencing XPATH or extraction functions indicative of error-based SQL injection.
  • Logs: Multiple rapid requests to the same endpoint from a single authenticated session, potentially indicating automated SQL injection tooling (e.g., sqlmap).
  • Database: Unexpected queries in the database slow query log or general query log involving EXTRACTVALUE, UPDATEXML, or BENCHMARK functions originating from the Chamilo web application user.

Mitigation and workarounds

The primary remediation is to upgrade Chamilo LMS to version 1.11.30 or later, which replaces vulnerable raw SQL concatenation with parameterized queries (Chamilo Release). If immediate patching is not feasible, restrict network-level access to /main/coursecopy/copy_course_session_selected.php via web server configuration or WAF rules to limit exposure to trusted IP ranges. Additionally, implement WAF rules to detect and block SQL injection patterns in POST body parameters, apply the principle of least privilege to the database account used by Chamilo, and monitor database and application logs for anomalous SQL activity (GitHub Advisory).

Community reactions

The vulnerability was discovered and reported by Aleksey Solovev of Positive Technologies, who is credited in the official GitHub Security Advisory. The Hacker Wire shared the disclosure on Bluesky and Mastodon shortly after publication. Community coverage was limited but included aggregation by Vulners, VulDB, and radar.offseq.com. No major vendor statements beyond the Chamilo project's own advisory and patch release have been identified.

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management