
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-50191 is an error-based SQL Injection vulnerability in Chamilo LMS, a widely used open-source learning management system. The flaw exists in the /main/exercise/hotpotatoes.php script, where the userFile POST parameter is not properly sanitized before being incorporated into SQL queries. All Chamilo LMS versions prior to 1.11.30 (specifically confirmed through 1.11.28) are affected. The vulnerability was disclosed on March 2, 2026, and patched in version 1.11.30. It carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 7.0 (High) (GitHub Advisory, Feedly).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), classified as a SQL Injection vulnerability. In the vulnerable code path within hotpotatoes.php, the filename from $_FILES['userFile']['name'] was used directly in SQL query construction without escaping on non-first upload steps — specifically, the $filename variable was only sanitized via api_replace_dangerous_char() during the first upload step, while subsequent steps used the raw value, which was then incorporated into a SELECT query using string concatenation rather than parameterized queries. The fix involved moving the api_replace_dangerous_char() call outside the conditional block so it applies universally, and replacing the raw string concatenation in the SELECT statement with Database::escape_string() (GitHub Commit, GitHub Advisory). Exploitation requires an authenticated session with administrator-level privileges.
A successful exploit allows an authenticated administrator to extract sensitive data from the Chamilo database, including user credentials, course content, and personal information stored within the LMS. The CVSS scoring reflects high confidentiality and availability impact, with no integrity impact on the vulnerable system itself. While the privilege requirement limits the attack surface, a compromised administrator account or an insider threat could leverage this vulnerability to exfiltrate the entire database or cause service disruption (GitHub Advisory, Feedly).
A proof-of-concept is referenced in the GitHub security advisory, but there is no evidence of active in-the-wild exploitation at this time (Feedly). The vulnerability was discovered and reported by Aleksey Solovev of Positive Technologies (GitHub Advisory). The EPSS score is approximately 0.026% (0.000260), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for high-privilege (administrator) authentication.
/main/exercise/hotpotatoes.php within a course context.$fld session variable.userFile filename contains a SQL injection payload (e.g., file' AND EXTRACTVALUE(1,CONCAT(0x7e,(SELECT version())))-- -) designed to trigger an error-based SQL injection response./main/exercise/hotpotatoes.php with the injected filename in the userFile field and the appropriate finish parameter set to a non-zero value to bypass the first-step sanitization path./main/exercise/hotpotatoes.php containing SQL metacharacters (e.g., single quotes, EXTRACTVALUE, UPDATEXML, AND 1=, OR 1=) in the userFile filename field; repeated requests to this endpoint from a single IP in a short timeframe./main/exercise/hotpotatoes.php with anomalous filename values containing SQL syntax; application error logs showing database query errors or MySQL error messages triggered by malformed SQL.hotpotatoes document table with malformed path values; unusual SELECT queries with error-generating functions like EXTRACTVALUE() or UPDATEXML()./HotPotatoes_files/) with unusual or SQL-fragment-like names.The primary remediation is to upgrade Chamilo LMS to version 1.11.30 or later, which contains the security patch (GitHub Release). The fix applies api_replace_dangerous_char() universally to the uploaded filename and replaces raw SQL string concatenation with Database::escape_string() for the path parameter in the SELECT query (GitHub Commit). As a temporary workaround prior to patching, administrators should restrict access to the /main/exercise/hotpotatoes.php endpoint to trusted administrator accounts only, and consider implementing a web application firewall (WAF) rule to block requests containing SQL injection patterns in file upload parameters (GitHub Advisory).
The vulnerability was discovered by Aleksey Solovev of Positive Technologies and responsibly disclosed through GitHub's security advisory process (GitHub Advisory). The Chamilo project maintainer (ywarnier) published the advisory on March 2, 2026, alongside the release of version 1.11.30 as a security patch release. Coverage has appeared on vulnerability tracking platforms including Vulners, VulDB, and Offseq Radar, with no significant broader media or social media discussion noted beyond standard CVE announcement channels.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."