CVE-2025-50195: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-50195 is an OS Command Injection vulnerability in Chamilo LMS, a widely used open-source learning management system. The flaw resides in the VChamilo plugin's /plugin/vchamilo/views/manage.controller.php file and allows an authenticated administrator to execute arbitrary operating system commands on the server. It affects all Chamilo LMS versions prior to 1.11.30 (specifically confirmed through 1.11.28), and was disclosed on March 2, 2026. The vulnerability carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 7.1 (High) (GitHub Advisory, Feedly).

Technical details

The root cause is insufficient server-side input validation of the main_database POST parameter in the VChamilo plugin's manage controller, classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command) (GitHub Advisory). User-supplied data from this parameter is passed unsanitized to the operating system shell, enabling injection of arbitrary commands. The fix introduced a clearDatabaseName() method in Database class that strips all characters except alphanumerics, underscores, and hyphens (preg_replace('/[^a-zA-Z0-9_\-]/', '', $dbName)) and applied it to the main_database and import_to_main_database fields in plugin/vchamilo/lib/Virtual.php (GitHub Commit). Exploitation requires an authenticated session with administrator-level privileges; no user interaction beyond authentication is needed.

Impact

A successful exploit allows an authenticated administrator to execute arbitrary OS commands in the context of the web server process, resulting in high integrity and availability impact and low-to-high confidentiality impact on the vulnerable system (GitHub Advisory). This could lead to complete server compromise, unauthorized access to sensitive LMS data (student records, credentials, course content), modification or deletion of system files, and denial of service. Lateral movement to other systems on the same network is possible if the web server process has sufficient privileges or network access.

Exploitability

A proof-of-concept exploit is referenced in the GitHub security advisory, discovered by researcher Nikolay Archakov of Positive Technologies (GitHub Advisory). As of the disclosure date, there is no evidence of active in-the-wild exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.643%, indicating a relatively low (but non-negligible) probability of exploitation in the near term (Feedly). Exploitation is constrained by the requirement for high-privilege (administrator) credentials.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Chamilo LMS instances running versions prior to 1.11.30 using search engines (e.g., Shodan, Censys) or by checking the Chamilo version disclosure on the login page.
  2. Obtain administrator credentials: Acquire valid administrator-level credentials through phishing, credential stuffing, or other means — exploitation requires an authenticated admin session.
  3. Authenticate: Log in to the Chamilo admin panel using the obtained credentials.
  4. Navigate to VChamilo plugin: Access the VChamilo plugin management interface, which processes requests through /plugin/vchamilo/views/manage.controller.php.
  5. Craft malicious POST request: Submit a POST request to the VChamilo manage controller with a crafted main_database parameter containing OS command injection payloads (e.g., validname; id or validname$(whoami)) that bypass the absent input validation.
  6. Achieve command execution: The injected command is passed to the OS shell and executed in the context of the web server process, enabling actions such as spawning a reverse shell, exfiltrating data, or creating backdoor accounts (GitHub Advisory, GitHub Commit).

Indicators of compromise

  • Network: Unexpected outbound connections from the Chamilo web server to external IPs (potential reverse shell callbacks); unusual DNS lookups originating from the web server process.
  • Logs: Web server access logs showing POST requests to /plugin/vchamilo/views/manage.controller.php with anomalous or shell-metacharacter-containing main_database values (e.g., ;, $(), |, backticks); PHP error logs showing unexpected command execution errors.
  • File System: New or modified files in the Chamilo web root or /tmp directory (e.g., web shells, scripts); unexpected cron jobs or scheduled tasks added under the web server user account.
  • Process: Unusual child processes spawned by the PHP/web server process (e.g., /bin/sh, bash, curl, wget, nc, python) visible in process listings or audit logs (GitHub Advisory).

Mitigation and workarounds

Upgrade Chamilo LMS to version 1.11.30 or later, which introduces the clearDatabaseName() sanitization method to strip shell-special characters from the main_database parameter (GitHub Release, GitHub Commit). As interim mitigations, restrict network-level access to the Chamilo admin panel (e.g., via firewall rules or VPN), limit administrator account usage to trusted personnel only, and monitor admin activity logs for suspicious command patterns. Implementing server-side input whitelisting and separating data from commands (parameterization) are recommended long-term hardening measures (GitHub Advisory).

Community reactions

The vulnerability was discovered and reported by Nikolay Archakov of Positive Technologies, a well-known security research firm (GitHub Advisory). The Chamilo project maintainer (ywarnier) published the security advisory and patch promptly on March 2, 2026. No significant broader media coverage or notable social media discussion beyond standard vulnerability tracking feeds has been observed for this CVE.

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management