CVE-2025-50192: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-50192 is a time-based SQL injection vulnerability in Chamilo LMS affecting the SOAP web services endpoint /main/webservices/registration.soap.php. It was disclosed on March 2, 2026, and affects all Chamilo LMS versions prior to 1.11.30 (specifically confirmed through 1.11.28). The vulnerability was discovered by Aleksey Solovev of Positive Technologies and patched in version 1.11.30. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 score of 8.8 (High) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), classified as a time-based blind SQL injection (CAPEC-7). Specifically, the WSCertificatesList function in /main/webservices/registration.soap.php directly interpolated user-supplied $startingDate and $endingDate parameters into SQL WHERE clauses using string concatenation without sanitization or parameterization, enabling an attacker to inject arbitrary SQL logic. The fix replaced raw string concatenation with parameterized queries using Database::select() with bound parameters (GitHub Commit, GitHub Advisory). No authentication or user interaction is required to exploit this endpoint.

Impact

An unauthenticated remote attacker can exploit this vulnerability to extract sensitive database contents including user credentials, course data, and certificate records from the Chamilo LMS database. The high confidentiality and availability impacts mean that successful exploitation could result in unauthorized access to educational platform data and potential service disruption. While integrity impact is rated None in CVSS v4.0, the exposure of credential data could enable further account takeover and lateral movement within the platform (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly available via the GitHub security advisory, though there is no confirmed evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability requires no authentication, no user interaction, and is network-accessible, making it trivially exploitable. The EPSS score is approximately 0.029% (0.000290), indicating low but non-zero probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. The researcher credited is Aleksey Solovev of Positive Technologies (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Chamilo LMS instances running versions prior to 1.11.30 using search engines (Shodan, Censys) or by checking the Chamilo version disclosure on the login page.
  2. Locate the vulnerable endpoint: Target the SOAP web service at /main/webservices/registration.soap.php, which is publicly accessible without authentication.
  3. Craft a time-based SQL injection payload: Inject a time-delay payload (e.g., using MySQL SLEEP() or BENCHMARK()) into the startingDate or endingDate SOAP parameters passed to the WSCertificatesList function. Example: startingDate = '2024-01-01' AND SLEEP(5)-- -.
  4. Infer database contents: Use conditional time-delay logic to extract data character by character (e.g., IF(SUBSTRING(username,1,1)='a', SLEEP(5), 0)) from the user table or other database tables.
  5. Automate extraction: Use tools such as sqlmap with the --technique=T (time-based blind) flag targeting the SOAP endpoint to automate credential and data extraction.
  6. Leverage extracted credentials: Use harvested usernames and password hashes to attempt account takeover on the Chamilo platform or related systems (GitHub Advisory, GitHub Commit).

Indicators of compromise

  • Network: Unusual or repeated SOAP requests to /main/webservices/registration.soap.php from external IP addresses, particularly with abnormal or malformed date parameters; high-latency responses from the endpoint suggesting time-delay SQL injection activity.
  • Logs: Web server access logs showing repeated POST requests to /main/webservices/registration.soap.php with encoded or suspicious parameter values; database slow query logs showing repeated SLEEP() or BENCHMARK() calls originating from the web application user.
  • Application Logs: Chamilo application logs showing unexpected errors or exceptions from the WSCertificatesList function or related SOAP handlers.
  • Process: Unusual database query patterns with time-delay functions (SLEEP, BENCHMARK) associated with the Chamilo database user account.

Mitigation and workarounds

The primary remediation is to upgrade Chamilo LMS to version 1.11.30 or later, which replaces vulnerable string-concatenated SQL queries with parameterized statements in the SOAP registration script (GitHub Release, GitHub Commit). As a temporary workaround, administrators should consider restricting network access to /main/webservices/registration.soap.php via firewall rules or web server configuration (e.g., IP allowlisting) if the SOAP endpoint is not required for external access. Additionally, review access logs for the vulnerable endpoint for signs of prior exploitation and enforce least-privilege database permissions for the Chamilo web application user (GitHub Advisory).

Community reactions

The vulnerability was reported by Aleksey Solovev of Positive Technologies and published via GitHub's security advisory system on March 2, 2026. Coverage appeared on security aggregators including Vulners, VulDB, and The Hacker Wire shortly after disclosure. Social media mentions were observed on Bluesky and Mastodon, primarily from automated CVE notification accounts. No major vendor statements beyond the Chamilo project's own advisory and patch release have been identified (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management