CVE-2025-50191: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-50191 is an error-based SQL Injection vulnerability in Chamilo LMS, a widely used open-source learning management system. The flaw exists in the /main/exercise/hotpotatoes.php script, where the userFile POST parameter is not properly sanitized before being incorporated into SQL queries. All Chamilo LMS versions prior to 1.11.30 (specifically confirmed through 1.11.28) are affected. The vulnerability was disclosed on March 2, 2026, and patched in version 1.11.30. It carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 7.0 (High) (GitHub Advisory, Feedly).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), classified as a SQL Injection vulnerability. In the vulnerable code path within hotpotatoes.php, the filename from $_FILES['userFile']['name'] was used directly in SQL query construction without escaping on non-first upload steps — specifically, the $filename variable was only sanitized via api_replace_dangerous_char() during the first upload step, while subsequent steps used the raw value, which was then incorporated into a SELECT query using string concatenation rather than parameterized queries. The fix involved moving the api_replace_dangerous_char() call outside the conditional block so it applies universally, and replacing the raw string concatenation in the SELECT statement with Database::escape_string() (GitHub Commit, GitHub Advisory). Exploitation requires an authenticated session with administrator-level privileges.

Impact

A successful exploit allows an authenticated administrator to extract sensitive data from the Chamilo database, including user credentials, course content, and personal information stored within the LMS. The CVSS scoring reflects high confidentiality and availability impact, with no integrity impact on the vulnerable system itself. While the privilege requirement limits the attack surface, a compromised administrator account or an insider threat could leverage this vulnerability to exfiltrate the entire database or cause service disruption (GitHub Advisory, Feedly).

Exploitability

A proof-of-concept is referenced in the GitHub security advisory, but there is no evidence of active in-the-wild exploitation at this time (Feedly). The vulnerability was discovered and reported by Aleksey Solovev of Positive Technologies (GitHub Advisory). The EPSS score is approximately 0.026% (0.000260), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for high-privilege (administrator) authentication.

Exploitation steps

  1. Authenticate as Administrator: Obtain valid administrator credentials for the target Chamilo LMS instance (versions prior to 1.11.30) through phishing, credential stuffing, or insider access.
  2. Navigate to HotPotatoes Upload: Access the HotPotatoes exercise upload functionality at /main/exercise/hotpotatoes.php within a course context.
  3. Initiate a multi-step upload: Submit an initial file upload POST request to complete the first step, which creates the upload folder and sets the $fld session variable.
  4. Craft malicious filename payload: On the subsequent (non-first) upload step, craft a POST request where the userFile filename contains a SQL injection payload (e.g., file' AND EXTRACTVALUE(1,CONCAT(0x7e,(SELECT version())))-- -) designed to trigger an error-based SQL injection response.
  5. Send the malicious request: Submit the crafted POST request to /main/exercise/hotpotatoes.php with the injected filename in the userFile field and the appropriate finish parameter set to a non-zero value to bypass the first-step sanitization path.
  6. Extract data from error responses: Observe the database error messages returned in the HTTP response, which leak database contents (e.g., version, table names, user credentials) via the error-based injection technique.
  7. Iterate to exfiltrate: Repeat with modified payloads to enumerate and extract target data from the Chamilo database (GitHub Advisory, GitHub Commit).

Indicators of compromise

  • Network: Unusual POST requests to /main/exercise/hotpotatoes.php containing SQL metacharacters (e.g., single quotes, EXTRACTVALUE, UPDATEXML, AND 1=, OR 1=) in the userFile filename field; repeated requests to this endpoint from a single IP in a short timeframe.
  • Logs: Web server access logs showing POST requests to /main/exercise/hotpotatoes.php with anomalous filename values containing SQL syntax; application error logs showing database query errors or MySQL error messages triggered by malformed SQL.
  • Database: Unexpected or unauthorized queries in the database query log referencing the hotpotatoes document table with malformed path values; unusual SELECT queries with error-generating functions like EXTRACTVALUE() or UPDATEXML().
  • File System: Unexpected files or folders created under the HotPotatoes upload directory (/HotPotatoes_files/) with unusual or SQL-fragment-like names.

Mitigation and workarounds

The primary remediation is to upgrade Chamilo LMS to version 1.11.30 or later, which contains the security patch (GitHub Release). The fix applies api_replace_dangerous_char() universally to the uploaded filename and replaces raw SQL string concatenation with Database::escape_string() for the path parameter in the SELECT query (GitHub Commit). As a temporary workaround prior to patching, administrators should restrict access to the /main/exercise/hotpotatoes.php endpoint to trusted administrator accounts only, and consider implementing a web application firewall (WAF) rule to block requests containing SQL injection patterns in file upload parameters (GitHub Advisory).

Community reactions

The vulnerability was discovered by Aleksey Solovev of Positive Technologies and responsibly disclosed through GitHub's security advisory process (GitHub Advisory). The Chamilo project maintainer (ywarnier) published the advisory on March 2, 2026, alongside the release of version 1.11.30 as a security patch release. Coverage has appeared on vulnerability tracking platforms including Vulners, VulDB, and Offseq Radar, with no significant broader media or social media discussion noted beyond standard CVE announcement channels.

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management