CVE-2025-50197: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-50197 is an OS Command Injection vulnerability in Chamilo LMS, a widely used open-source learning management system. The flaw exists in /main/admin/sub_language_ajax.inc.php and is exploitable via the POST new_language parameter, allowing an authenticated administrator to execute arbitrary operating system commands on the server. All Chamilo LMS versions prior to 1.11.30 (specifically confirmed through 1.11.28) are affected. The vulnerability was disclosed on March 2, 2026, and patched in version 1.11.30. It carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 7.1 (High) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command). The vulnerable component, /main/admin/sub_language_ajax.inc.php, accepted the new_language POST parameter and passed it to OS-level operations without adequate sanitization — only applying XSS removal via Security::remove_XSS(), which is insufficient to prevent command injection. The fix (commit e1c7879) introduced input whitelisting via a regex pattern (/^[a-zA-Z_][a-zA-Z0-9_]*$/) for the variable_language parameter and moved string escaping logic into the write_data_in_file() method using addcslashes(). Exploitation requires an authenticated session with administrator-level privileges, limiting the attack surface but not eliminating risk in environments with compromised or malicious admin accounts (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an authenticated administrator to execute arbitrary OS commands in the context of the web server process, resulting in high impact to confidentiality, integrity, and availability of the affected system. An attacker could read sensitive files, modify or delete system data, install backdoors or web shells, and potentially disrupt service availability. While the vulnerability does not directly affect subsequent systems (lateral movement is not inherent), a compromised server could serve as a pivot point for further attacks within the network (GitHub Advisory).

Exploitability

A proof-of-concept exploit is referenced in the GitHub Security Advisory, but there is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.64%, indicating a low but non-negligible probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high-privilege (administrator) credentials, which significantly limits the attacker pool but does not eliminate risk from insider threats or credential compromise scenarios (GitHub Advisory, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Chamilo LMS instances running versions prior to 1.11.30 using search engines (e.g., Shodan, Censys) or by checking the Chamilo version disclosure on the login page.
  2. Obtain Administrator Credentials: Acquire valid administrator credentials through phishing, credential stuffing, brute force, or insider access — exploitation requires the administrator role.
  3. Authenticate: Log in to the Chamilo LMS admin panel using the obtained credentials to establish an authenticated session.
  4. Craft Malicious Request: Send a crafted HTTP POST request to /main/admin/sub_language_ajax.inc.php with the new_language parameter containing an OS command injection payload (e.g., appending shell metacharacters or command separators to inject arbitrary commands).
  5. Execute Arbitrary Commands: The injected payload is passed to the OS shell without adequate sanitization, resulting in execution of arbitrary commands in the context of the web server process (e.g., www-data).
  6. Establish Persistence: Use the command execution capability to deploy a web shell, create a backdoor user, or exfiltrate sensitive data from the server (GitHub Advisory, Patch Commit).

Indicators of compromise

  • Network: Unusual or unexpected outbound connections from the Chamilo web server process to external IPs; HTTP POST requests to /main/admin/sub_language_ajax.inc.php with anomalous or oversized new_language parameter values containing shell metacharacters (;, |, &&, backticks).
  • Logs: Web server access logs showing POST requests to /main/admin/sub_language_ajax.inc.php from admin accounts at unusual times or from unexpected IP addresses; PHP error logs indicating unexpected command execution or file write operations.
  • File System: Newly created or modified PHP files in the Chamilo web root or language directories (e.g., *.inc.php) with unexpected content; presence of web shells (e.g., files containing eval, system, exec, passthru functions) in the application directory.
  • Process: Unusual child processes spawned by the web server process (e.g., apache2, nginx, php-fpm) such as /bin/sh, bash, curl, wget, nc, or python; unexpected cron jobs or scheduled tasks created under the web server user account.

Mitigation and workarounds

Upgrade Chamilo LMS to version 1.11.30 or later, which addresses this vulnerability by implementing input whitelisting (regex validation) for the variable_language parameter and proper escaping in the write_data_in_file() method (Chamilo Release, Patch Commit). As a workaround for environments that cannot immediately upgrade, restrict network access to the /main/admin/sub_language_ajax.inc.php endpoint to trusted IP addresses only, and enforce the principle of least privilege for administrator accounts. Additionally, monitor administrative activity on language configuration pages and implement multi-factor authentication for admin accounts to reduce the risk of credential compromise.

Community reactions

The vulnerability was discovered and reported by Vladimir Vlasov of Positive Technologies, as credited in the GitHub Security Advisory (GitHub Advisory). The Chamilo project responded promptly with a patch in version 1.11.30, released as a security patch on top of 1.11.28. No significant broader media coverage or notable community debate has been observed beyond standard vulnerability database entries and automated security feeds.

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management