CVE-2025-50193: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-50193 is an OS command injection vulnerability in Chamilo LMS affecting the VChamilo plugin's import functionality. The flaw exists in /plugin/vchamilo/views/import.php via the POST to_main_database parameter, allowing authenticated administrators to execute arbitrary OS commands on the server. All Chamilo LMS versions prior to 1.11.30 (specifically confirmed through 1.11.28) are affected. The vulnerability was disclosed on March 2, 2026, and patched in version 1.11.30. It carries a CVSS v3.1 score of 7.2 (High) and a CVSS v4.0 score of 7.1 (High) (GitHub Advisory, Red Hat).

Technical details

The root cause is insufficient server-side input validation of the to_main_database POST parameter in the VChamilo plugin's import handler (CWE-78: Improper Neutralization of Special Elements used in an OS Command). The application passes user-supplied data directly to OS-level operations without sanitization, enabling injection of arbitrary shell commands. Exploitation requires an authenticated session with administrator privileges. The fix, introduced in commit afdbd4b, adds a clearDatabaseName() method that strips all characters except alphanumerics, underscores, and hyphens using preg_replace('/[^a-zA-Z0-9_\-]/', '', $dbName) before the value is used (GitHub Commit, GitHub Advisory).

Impact

Successful exploitation allows an authenticated attacker with administrator privileges to execute arbitrary OS commands in the context of the web server process, potentially leading to complete system compromise. This includes unauthorized access to sensitive data (confidentiality impact), modification or deletion of system files and course data (integrity impact), and disruption of the LMS service (availability impact). Given that Chamilo LMS is widely used in educational institutions, exploitation could expose student records, credentials, and other sensitive institutional data (GitHub Advisory).

Exploitability

A proof-of-concept exploit is referenced in the GitHub security advisory, though no evidence of active in-the-wild exploitation has been reported as of the disclosure date. Exploitation requires high privileges (administrator role), which limits the attack surface compared to unauthenticated vulnerabilities. The EPSS score is approximately 0.64%, indicating a relatively low probability of near-term exploitation. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was discovered and reported by Nikolay Archakov of Positive Technologies (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Chamilo LMS instances running versions prior to 1.11.30 using search engines (Shodan, Censys) or web fingerprinting tools targeting Chamilo-specific paths.
  2. Authentication: Obtain or compromise administrator credentials for the target Chamilo LMS instance through phishing, credential stuffing, or other means.
  3. Navigate to vulnerable endpoint: Access the VChamilo plugin import functionality at /plugin/vchamilo/views/import.php while authenticated as an administrator.
  4. Craft malicious payload: Prepare a POST request with the to_main_database parameter containing OS command injection syntax (e.g., legitimate_db_name; id or using backticks/$() subshell syntax to append arbitrary commands).
  5. Submit the request: Send the crafted POST request to the vulnerable endpoint using a browser, Burp Suite, or curl.
  6. Achieve code execution: The injected command executes with the privileges of the web server process (e.g., www-data), enabling reverse shell establishment, data exfiltration, or further lateral movement within the server environment (GitHub Advisory, GitHub Commit).

Indicators of compromise

  • Network: Unexpected outbound connections from the web server process to external IPs (reverse shell attempts); unusual DNS lookups originating from the Chamilo server process.
  • Logs: Web server access logs showing POST requests to /plugin/vchamilo/views/import.php with anomalous or encoded to_main_database parameter values containing shell metacharacters (;, |, `, $()).
  • Process: Unusual child processes spawned by the PHP/web server process (e.g., /bin/bash, /bin/sh, curl, wget, nc, python) visible in process trees.
  • File System: Unexpected new files (web shells, scripts, cron jobs) created in the Chamilo installation directory or /tmp by the web server user account; modification timestamps on system files inconsistent with normal operations.

Mitigation and workarounds

The primary remediation is to upgrade Chamilo LMS to version 1.11.30 or later, which introduces the clearDatabaseName() sanitization method to strip dangerous characters from the to_main_database parameter (GitHub Release). For organizations unable to patch immediately, restrict access to /plugin/vchamilo/views/import.php at the web server or network level to only trusted administrative IP addresses. Additionally, implement network-level access controls (firewall rules, WAF rules) to limit exposure of the Chamilo admin interface, and review access logs for any suspicious POST requests to the vulnerable endpoint (GitHub Advisory).

Community reactions

The vulnerability was discovered by Nikolay Archakov of Positive Technologies and responsibly disclosed to the Chamilo project, resulting in a coordinated patch release. The advisory was published by Chamilo maintainer ywarnier on GitHub on March 2, 2026. No significant broader media coverage or notable community discussion beyond the official advisory and standard vulnerability database entries has been observed (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management