CVE-2025-50194: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-50194 is an OS Command Injection vulnerability in Chamilo LMS, a widely used open-source learning management system. The flaw exists in /main/cron/lang/check_parse_lang.php (with the root cause in main/admin/sub_language_add.php) and affects all versions prior to 1.11.30 (specifically confirmed through version 1.11.28). It was disclosed on March 2, 2026, by researcher Vladimir Vlasov of Positive Technologies, and patched in version 1.11.30. The vulnerability carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 7.1 (High) (GitHub Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command) and stems from insufficient server-side validation of the english_name POST parameter in main/admin/sub_language_add.php. The application previously only replaced spaces with underscores (str_replace(' ', '_', $english_name)) before passing the value to OS-level operations, allowing an attacker to inject shell metacharacters or command delimiters. Exploitation requires an authenticated session with administrator-level privileges and is conducted over the network with no user interaction required. The fix replaces the naive sanitization with a call to api_replace_dangerous_char(), which strips or escapes dangerous characters before use (GitHub Advisory, GitHub Commit).

Impact

Successful exploitation allows an authenticated administrator to execute arbitrary OS commands on the application server in the context of the web server process. This can result in full system compromise, including unauthorized access to sensitive data (e.g., student records, credentials), modification or deletion of system files, and disruption of service availability. While the vulnerability requires high privileges, a compromised or malicious administrator account could leverage it for lateral movement within the hosting environment (GitHub Advisory, Feedly).

Exploitability

A proof-of-concept reference is available via the GitHub Security Advisory, though no weaponized exploit code or active in-the-wild exploitation has been reported as of the time of disclosure (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.643%, indicating a low but non-negligible probability of exploitation in the near term (Feedly). Exploitation is constrained by the requirement for administrator-level credentials, which limits the attacker pool.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Chamilo LMS instances running versions prior to 1.11.30 using tools like Shodan or Censys, searching for Chamilo-specific HTTP headers or login pages.
  2. Obtain administrator credentials: Acquire valid administrator credentials through phishing, credential stuffing, or by compromising an existing admin account.
  3. Authenticate: Log in to the Chamilo LMS admin panel using the obtained credentials.
  4. Navigate to sub-language creation: Access the sub-language administration page at /main/admin/sub_language_add.php.
  5. Inject OS command payload: Submit the sub-language creation form with a crafted english_name POST parameter containing shell metacharacters (e.g., validname; id or validname$(whoami)) to inject an arbitrary OS command.
  6. Trigger execution: The application passes the unsanitized input to an OS-level operation via /main/cron/lang/check_parse_lang.php, executing the injected command in the context of the web server process.
  7. Achieve objective: Collect command output, establish a reverse shell, exfiltrate data, or perform further actions on the compromised server (GitHub Advisory, GitHub Commit).

Indicators of compromise

  • Network: Unusual outbound connections from the web server process to external IPs following requests to /main/admin/sub_language_add.php or /main/cron/lang/check_parse_lang.php; unexpected DNS lookups from the server.
  • Logs: Web server access logs showing POST requests to /main/admin/sub_language_add.php with english_name values containing shell metacharacters (;, $(), |, `); PHP error logs referencing unexpected command execution.
  • File System: New or modified files in the Chamilo installation directory, particularly web shells or scripts created by the web server user; unexpected cron jobs added under the web server account.
  • Process: Unusual child processes spawned by the PHP/web server process (e.g., /bin/sh, bash, curl, wget, nc, python) visible in process listings or audit logs (GitHub Advisory).

Mitigation and workarounds

The primary remediation is to upgrade Chamilo LMS to version 1.11.30 or later, which replaces the vulnerable input handling with a call to api_replace_dangerous_char() in main/admin/sub_language_add.php (GitHub Commit, Release Notes). As a temporary workaround, restrict network-level access to /main/admin/sub_language_add.php and /main/cron/lang/check_parse_lang.php to trusted administrator IPs only. Additionally, review and minimize the number of accounts with administrator privileges, and monitor logs for suspicious activity targeting these endpoints (GitHub Advisory).

Community reactions

The vulnerability was discovered and reported by Vladimir Vlasov of Positive Technologies, a well-known security research firm (GitHub Advisory). The Chamilo project maintainers responded promptly, publishing the advisory and patch on March 2, 2026. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability database entries.

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management