
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-50193 is an OS command injection vulnerability in Chamilo LMS affecting the VChamilo plugin's import functionality. The flaw exists in /plugin/vchamilo/views/import.php via the POST to_main_database parameter, allowing authenticated administrators to execute arbitrary OS commands on the server. All Chamilo LMS versions prior to 1.11.30 (specifically confirmed through 1.11.28) are affected. The vulnerability was disclosed on March 2, 2026, and patched in version 1.11.30. It carries a CVSS v3.1 score of 7.2 (High) and a CVSS v4.0 score of 7.1 (High) (GitHub Advisory, Red Hat).
The root cause is insufficient server-side input validation of the to_main_database POST parameter in the VChamilo plugin's import handler (CWE-78: Improper Neutralization of Special Elements used in an OS Command). The application passes user-supplied data directly to OS-level operations without sanitization, enabling injection of arbitrary shell commands. Exploitation requires an authenticated session with administrator privileges. The fix, introduced in commit afdbd4b, adds a clearDatabaseName() method that strips all characters except alphanumerics, underscores, and hyphens using preg_replace('/[^a-zA-Z0-9_\-]/', '', $dbName) before the value is used (GitHub Commit, GitHub Advisory).
Successful exploitation allows an authenticated attacker with administrator privileges to execute arbitrary OS commands in the context of the web server process, potentially leading to complete system compromise. This includes unauthorized access to sensitive data (confidentiality impact), modification or deletion of system files and course data (integrity impact), and disruption of the LMS service (availability impact). Given that Chamilo LMS is widely used in educational institutions, exploitation could expose student records, credentials, and other sensitive institutional data (GitHub Advisory).
A proof-of-concept exploit is referenced in the GitHub security advisory, though no evidence of active in-the-wild exploitation has been reported as of the disclosure date. Exploitation requires high privileges (administrator role), which limits the attack surface compared to unauthenticated vulnerabilities. The EPSS score is approximately 0.64%, indicating a relatively low probability of near-term exploitation. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was discovered and reported by Nikolay Archakov of Positive Technologies (GitHub Advisory).
/plugin/vchamilo/views/import.php while authenticated as an administrator.to_main_database parameter containing OS command injection syntax (e.g., legitimate_db_name; id or using backticks/$() subshell syntax to append arbitrary commands).curl.www-data), enabling reverse shell establishment, data exfiltration, or further lateral movement within the server environment (GitHub Advisory, GitHub Commit)./plugin/vchamilo/views/import.php with anomalous or encoded to_main_database parameter values containing shell metacharacters (;, |, `, $())./bin/bash, /bin/sh, curl, wget, nc, python) visible in process trees./tmp by the web server user account; modification timestamps on system files inconsistent with normal operations.The primary remediation is to upgrade Chamilo LMS to version 1.11.30 or later, which introduces the clearDatabaseName() sanitization method to strip dangerous characters from the to_main_database parameter (GitHub Release). For organizations unable to patch immediately, restrict access to /plugin/vchamilo/views/import.php at the web server or network level to only trusted administrative IP addresses. Additionally, implement network-level access controls (firewall rules, WAF rules) to limit exposure of the Chamilo admin interface, and review access logs for any suspicious POST requests to the vulnerable endpoint (GitHub Advisory).
The vulnerability was discovered by Nikolay Archakov of Positive Technologies and responsibly disclosed to the Chamilo project, resulting in a coordinated patch release. The advisory was published by Chamilo maintainer ywarnier on GitHub on March 2, 2026. No significant broader media coverage or notable community discussion beyond the official advisory and standard vulnerability database entries has been observed (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."