CVE-2025-50196: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-50196 is an OS Command Injection vulnerability in Chamilo LMS affecting the VChamilo plugin's editinstance.php file. The vulnerability exists in all versions prior to 1.11.30 (specifically confirmed through 1.11.28), where the main_database POST parameter is passed unsanitized to OS-level operations. It was discovered by Nikolay Archakov of Positive Technologies and disclosed on March 2, 2026, with a patch released in version 1.11.30. The vulnerability carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 7.1 (High) (GitHub Advisory, Red Hat).

Technical details

The root cause is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command) and CWE-77 (Command Injection). The vulnerable component is /plugin/vchamilo/views/editinstance.php, which accepts the main_database POST parameter and passes it without adequate server-side sanitization to shell-level operations within plugin/vchamilo/lib/Virtual.php. The fix introduced a clearDatabaseName() method in Database class that strips all characters except alphanumerics, underscores, and hyphens via preg_replace('/[^a-zA-Z0-9_\-]/', '', $dbName), applied at multiple points in the addInstance() and importInstance() methods. Exploitation requires an authenticated session with administrator-level privileges (GitHub Advisory, Patch Commit).

Impact

A successful exploit allows an authenticated administrator to execute arbitrary OS commands in the context of the web server process, resulting in high impact to confidentiality, integrity, and availability of the affected system. This could lead to unauthorized data access or exfiltration, modification or deletion of data, service disruption, and potentially full compromise of the underlying server. Lateral movement within the network hosting the Chamilo LMS instance is also a realistic consequence (GitHub Advisory, Red Hat).

Exploitability

A proof-of-concept reference is available via the GitHub Security Advisory, but there is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.51%, indicating a low but non-negligible probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high privileges (administrator role), which limits the attack surface compared to unauthenticated vulnerabilities (GitHub Advisory, Red Hat).

Exploitation steps

  1. Reconnaissance: Identify Chamilo LMS instances running versions prior to 1.11.30 (up to 1.11.28) with the VChamilo plugin enabled, using web fingerprinting tools or Shodan searches for Chamilo login pages.
  2. Authentication: Obtain or compromise administrator credentials for the target Chamilo LMS instance. This may involve credential stuffing, phishing, or exploiting weak default credentials.
  3. Navigate to vulnerable endpoint: Log in as an administrator and navigate to the VChamilo plugin instance management page, which submits data to /plugin/vchamilo/views/editinstance.php.
  4. Craft malicious payload: Intercept the HTTP POST request (e.g., using Burp Suite) when creating or editing a VChamilo instance, and inject OS command injection payloads into the main_database parameter, such as legit_db; id or legit_db$(whoami) to chain arbitrary commands.
  5. Achieve code execution: The injected command is passed unsanitized to the server's OS shell via the addInstance() function in Virtual.php, executing with the privileges of the web server process (e.g., www-data), enabling reverse shell establishment, data exfiltration, or further lateral movement (GitHub Advisory, Patch Commit).

Indicators of compromise

  • Network: Unexpected outbound connections from the web server to external IPs following POST requests to /plugin/vchamilo/views/editinstance.php; reverse shell traffic on non-standard ports originating from the Chamilo server process.
  • Logs: Web server access logs showing POST requests to /plugin/vchamilo/views/editinstance.php with unusual or encoded values in the main_database parameter (e.g., containing semicolons, backticks, $(), or pipe characters); PHP error logs showing unexpected command execution output.
  • File System: Unexpected web shells or scripts written to the Chamilo installation directory or /tmp; new cron jobs or scheduled tasks created by the web server user (www-data).
  • Process: Unusual child processes spawned by the PHP/web server process (e.g., /bin/bash, curl, wget, nc, python) visible in process trees; unexpected database operations or new database creation events in MySQL/MariaDB logs.

Mitigation and workarounds

The primary remediation is to upgrade Chamilo LMS to version 1.11.30, which introduces the Database::clearDatabaseName() sanitization method applied to the main_database parameter in Virtual.php. Until patching is possible, administrators should restrict access to the /plugin/vchamilo/ directory via web server configuration (e.g., IP allowlisting), limit administrator account access to only trusted personnel, and deploy a web application firewall (WAF) rule to detect and block OS command injection patterns in POST parameters targeting editinstance.php. Monitoring system logs for suspicious command execution attempts is also recommended (GitHub Advisory, Release v1.11.30).

Community reactions

The vulnerability was discovered and reported by Nikolay Archakov of Positive Technologies, a well-known security research firm. The Chamilo project maintainer (ywarnier) published the GitHub Security Advisory on March 2, 2026, and the fix was included in the v1.11.30 release. Red Hat also tracked the CVE in their security advisory database. Community discussion was limited, with brief mentions on Bluesky and vulnerability aggregator platforms shortly after disclosure (GitHub Advisory, Red Hat).

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management