CVE-2025-52998: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-52998 is a PHAR deserialization bypass vulnerability in Chamilo LMS (Learning Management System) that allows attackers to perform PHP object injection via crafted PHAR archives. The vulnerability affects all versions of Chamilo LMS up to and including 1.11.28, and was patched in version 1.11.30. It was discovered by researcher Aleksey Solovev of Positive Technologies and disclosed on March 2, 2026. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 7.0 (High) (GitHub Advisory).

Technical details

The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data) and is rooted in the vChamilo plugin's plugin/vchamilo/views/import.php file. Prior security patches attempted to block PHAR deserialization by checking for the phar:// prefix in user-supplied path parameters (confFile, coursePath, homePath, uploadPath), but the check was case-sensitive — allowing bypasses using mixed-case variants such as pHaR:// or PHAR://. Additionally, the system relied on mime_content_type to validate uploaded files, which could be bypassed by crafting a valid PHAR archive disguised as a JPEG image (e.g., empty.jpg). When PHP file system functions like is_dir(), file_exists(), or is_readable() are called with attacker-controlled paths containing a phar:// wrapper, PHP automatically deserializes the PHAR manifest, enabling object injection and potentially arbitrary code execution (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an attacker to instantiate arbitrary PHP classes and fully control their properties, effectively manipulating the application's operational logic. This can lead to complete compromise of confidentiality, integrity, and availability — including remote code execution, unauthorized modification of course content and user records, data exfiltration, and service disruption. The vChamilo plugin context means exploitation could also affect virtual Chamilo instances managed through the plugin (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code has been observed, and there is no evidence of in-the-wild exploitation at this time. The vulnerability requires the attacker to have high-privilege access (per CVSS v4.0 metrics), as the vChamilo plugin's import functionality is an administrative feature — though the CVSS v3.1 score of 9.8 reflects a no-authentication-required scenario under certain conditions. The EPSS score is approximately 0.136%, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vChamilo plugin is not enabled by default, which limits the attack surface (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify Chamilo LMS instances running versions ≤1.11.28 with the vChamilo plugin enabled (not enabled by default). Check for accessible admin or plugin management interfaces.
  2. Craft malicious PHAR archive: Create a PHAR archive containing a serialized PHP object with a gadget chain suitable for the target application. Disguise the PHAR file as a legitimate image (e.g., evil.jpg) by prepending valid JPEG header bytes, since mime_content_type checks can be bypassed this way.
  3. Upload the PHAR file: Use an available file upload mechanism within Chamilo (e.g., course file upload) to upload the crafted PHAR-as-JPEG file to the server.
  4. Trigger PHAR deserialization: Navigate to the vChamilo plugin import page and submit a form with one of the path parameters (configuration_file, upload_path, course_path, or home_path) set to a mixed-case PHAR wrapper pointing to the uploaded file (e.g., pHaR:///path/to/uploaded/evil.jpg). The case-sensitive check in the vulnerable code fails to block this.
  5. Achieve code execution: When PHP evaluates the path using file_exists(), is_dir(), or is_readable(), the PHAR manifest is deserialized, instantiating the attacker's chosen PHP class and triggering the gadget chain — potentially resulting in remote code execution, file manipulation, or other malicious actions (GitHub Advisory, Patch Commit).

Indicators of compromise

  • Network: HTTP POST requests to plugin/vchamilo/views/import.php containing path parameters with mixed-case phar:// variants (e.g., pHaR://, PHAR://); unusual outbound connections from the web server process following such requests.
  • File System: Presence of PHAR archives disguised as image files (e.g., .jpg, .png) in Chamilo upload directories; unexpected PHP files or web shells created in the Chamilo installation directory; new or modified files in plugin/vchamilo/ directories.
  • Logs: Web server access logs showing POST requests to plugin/vchamilo/views/import.php with encoded or mixed-case phar:// strings in form parameters; PHP error logs showing deserialization-related exceptions or unexpected class instantiation.
  • Process: Unusual child processes spawned by the PHP-FPM or Apache web server process (e.g., bash, curl, wget, python); unexpected cron jobs or scheduled tasks created under the web server user account.

Mitigation and workarounds

Upgrade Chamilo LMS to version 1.11.30 or later, which fixes the vulnerability by converting path parameters to lowercase before performing the phar:// prefix check, ensuring case-insensitive validation (Patch Commit, Release v1.11.30). As a workaround for installations that cannot immediately upgrade, disable the vChamilo plugin — it is not enabled by default and must be explicitly activated. Additionally, implement network-level access controls to restrict access to the Chamilo admin interface and monitor for suspicious deserialization activity (GitHub Advisory).

Community reactions

The vulnerability was reported by Aleksey Solovev of Positive Technologies, a well-known security research firm. The advisory was published by the Chamilo project maintainers on GitHub on March 2, 2026, and the fix was credited to contributor AngelFQC. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability database aggregation (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management