CVE-2025-50190: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-50190 is an error-based SQL Injection vulnerability in Chamilo LMS, a widely used open-source learning management system. The flaw exists in the openid.assoc_handle GET parameter processed by the /index.php script, allowing unauthenticated attackers to inject arbitrary SQL commands. It affects all Chamilo LMS versions up to and including 1.11.28, and was patched in version 1.11.30. The vulnerability was published on March 2, 2026, and was discovered by Aleksey Solovev of Positive Technologies. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 score of 8.8 (High) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). In the vulnerable code within main/auth/openid/login.php, the openid.assoc_handle parameter from the GET request was directly interpolated into an SQL query string using sprintf() without sanitization or parameterization: $sql = sprintf("SELECT * FROM $openid_association WHERE assoc_handle = '%s'", $response['openid.assoc_handle']). The fix replaced this with a parameterized query using Database::select() with a prepared statement placeholder. Exploitation requires the OpenID module to be enabled on the target instance, which is disabled by default, reducing the effective attack surface (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an unauthenticated remote attacker to read sensitive data from the database (including user credentials, course content, and personal information), potentially modify database contents, and cause denial of service of the LMS platform. The high confidentiality and availability impact scores reflect the risk of full database exposure and service disruption. While integrity impact is rated None in the CVSS v4 scoring, the ability to manipulate SQL queries could still enable indirect data modification depending on database permissions (GitHub Advisory).

Exploitability

A proof-of-concept is referenced in the GitHub Security Advisory, though no evidence of active in-the-wild exploitation has been reported as of the time of disclosure. The EPSS score is approximately 0.029% (0.000290), indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is conditional on the OpenID module being enabled, which is off by default, limiting the exposed population (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Chamilo LMS instances running versions ≤1.11.28 using search engines like Shodan or Censys, or by checking the Chamilo version disclosure on the login page.
  2. Check OpenID module status: Attempt to access /index.php with an openid.assoc_handle parameter. If the OpenID module is disabled (default), the parameter will not be processed and exploitation will fail.
  3. Craft malicious GET request: Send a crafted HTTP GET request to the target's /index.php endpoint with a SQL injection payload in the openid.assoc_handle parameter, e.g.:
    GET /index.php?openid.assoc_handle='%20AND%201=CONVERT(int,(SELECT%20@@version))--%20- HTTP/1.1
  4. Extract error-based data: Observe database error messages returned in the HTTP response, which leak database contents (e.g., version, table names, user credentials) through the error-based injection technique.
  5. Enumerate database: Use tools like sqlmap targeting the openid.assoc_handle parameter to automate extraction of database schema, user tables, and credential hashes:
    sqlmap -u "https://target/index.php?openid.assoc_handle=test" -p openid.assoc_handle --technique=E --dbs
  6. Leverage extracted data: Use harvested credentials or session tokens to authenticate to the LMS as an administrator or user, enabling further access or lateral movement (GitHub Advisory, Patch Commit).

Indicators of compromise

  • Network: Unusual HTTP GET requests to /index.php containing SQL metacharacters (e.g., single quotes, AND, SELECT, CONVERT, UNION, --) in the openid.assoc_handle parameter; repeated requests from a single IP to the OpenID endpoint.
  • Logs: Web server access logs showing requests like GET /index.php?openid.assoc_handle='%20AND%20... with HTTP 200 or 500 responses; database error messages in application logs referencing the openid_association table.
  • Application Logs: PHP error logs containing SQL syntax errors or database exceptions triggered by malformed assoc_handle values, indicating active probing or exploitation attempts.
  • Database: Unexpected queries against the openid_association table with malformed or unusually long assoc_handle values visible in database query logs (if enabled).

Mitigation and workarounds

The primary remediation is to upgrade Chamilo LMS to version 1.11.30 or later, which replaces the vulnerable string-concatenated SQL query with a parameterized prepared statement (Chamilo Release, Patch Commit). If immediate patching is not feasible, disable the OpenID authentication module (it is disabled by default), which removes the vulnerable code path entirely. Additionally, deploy WAF rules to detect and block SQL injection patterns in the openid.assoc_handle GET parameter, and restrict network-level access to the /index.php OpenID endpoint where possible (GitHub Advisory).

Community reactions

The vulnerability was reported by Aleksey Solovev of Positive Technologies and disclosed via GitHub's security advisory system. Social media activity was observed on Bluesky and Mastodon shortly after disclosure, with automated CVE notification accounts amplifying the advisory. Coverage was also noted on The Hacker Wire and security aggregators such as Vulners and VulDB. No major vendor statements beyond the Chamilo project's own advisory and patch release have been identified (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management