
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-50189 is an error-based SQL injection vulnerability in Chamilo LMS, an open-source learning management system. The flaw exists in /main/coursecopy/copy_course_session_selected.php, where insufficient validation of the POST resource[document][SQL_INJECTION_HERE] and login parameters allows authenticated attackers to inject arbitrary SQL statements and manipulate database query logic. All Chamilo LMS versions prior to 1.11.30 (specifically ≤1.11.28) are affected. The vulnerability was published on March 2, 2026, and patched in version 1.11.30. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 7.2 (High) (GitHub Advisory, Red Hat CVE).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), arising from direct string concatenation of user-supplied POST parameters into SQL queries within the CourseSelectForm::get_posted_course() method in src/Chamilo/CourseBundle/Component/CourseCopy/CourseSelectForm.php. The vulnerable code used raw Database::query($sql) calls where the $resource_item variable — derived from the POST resource[document] array keys — was inserted directly into the SQL string without sanitization or parameterization. An attacker with at least a trainer-level (low-privilege) authenticated session can craft a malicious POST request to /main/coursecopy/copy_course_session_selected.php with injected SQL in the document resource key or login parameter. The fix replaced raw query construction with parameterized Database::select() calls using prepared statement-style ? placeholders (GitHub Advisory, Patch Commit).
Successful exploitation allows an authenticated low-privileged attacker to read sensitive data from the database (high confidentiality impact), potentially including user credentials, course content, and personal information of students and instructors. The attacker can also manipulate or delete database records (high integrity impact) and cause denial of service through destructive SQL operations (high availability impact). The attack requires only network access and a minimal trainer-level account, with no user interaction needed, making it accessible to any enrolled or registered user on the platform (GitHub Advisory).
A proof-of-concept reference is available via the GitHub Security Advisory, and a technical write-up was published at infinitsec.net shortly after disclosure. The EPSS score is approximately 0.05%, indicating low current exploitation probability. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid authenticated session with at minimum a trainer role, limiting the attack surface compared to unauthenticated vulnerabilities (GitHub Advisory).
/main/coursecopy/copy_course_session_selected.php with a crafted resource[document] array key containing an SQL injection payload (e.g., resource[document][1 AND EXTRACTVALUE(1,CONCAT(0x7e,(SELECT version())))]) or inject into the login POST parameter.EXTRACTVALUE or similar error-based SQL functions./main/coursecopy/copy_course_session_selected.php containing SQL keywords (e.g., SELECT, UNION, EXTRACTVALUE, CONCAT, 0x) in the resource[document] parameter keys or login parameter.EXTRACTVALUE, UPDATEXML, or BENCHMARK functions originating from the Chamilo web application user.The primary remediation is to upgrade Chamilo LMS to version 1.11.30 or later, which replaces vulnerable raw SQL concatenation with parameterized queries (Chamilo Release). If immediate patching is not feasible, restrict network-level access to /main/coursecopy/copy_course_session_selected.php via web server configuration or WAF rules to limit exposure to trusted IP ranges. Additionally, implement WAF rules to detect and block SQL injection patterns in POST body parameters, apply the principle of least privilege to the database account used by Chamilo, and monitor database and application logs for anomalous SQL activity (GitHub Advisory).
The vulnerability was discovered and reported by Aleksey Solovev of Positive Technologies, who is credited in the official GitHub Security Advisory. The Hacker Wire shared the disclosure on Bluesky and Mastodon shortly after publication. Community coverage was limited but included aggregation by Vulners, VulDB, and radar.offseq.com. No major vendor statements beyond the Chamilo project's own advisory and patch release have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."