CVE-2026-28430: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2026-28430 is a critical unauthenticated SQL injection vulnerability in Chamilo LMS, a widely used open-source learning management system. It affects all versions up to and including 1.11.32, and was disclosed on March 15–16, 2026 via a GitHub Security Advisory. The flaw allows remote attackers to execute arbitrary SQL commands through the custom_dates parameter without any authentication, and can be chained with a predictable legacy password reset mechanism to achieve full administrative account takeover. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (GitHub Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input in the custom_dates parameter is incorporated into SQL queries without adequate sanitization or parameterization (GitHub Advisory). The attack vector is network-accessible, requires no authentication, no user interaction, and no special privileges, making it trivially exploitable by any remote attacker. A particularly dangerous attack chain exists: the SQL injection can be used to extract or manipulate data, which is then combined with Chamilo's predictable legacy password reset mechanism to take over administrator accounts without any prior credentials (GitHub Advisory). The vulnerability was verified in version 1.11.32 and is credited to researcher Kr1shna4garwal.

Impact

Successful exploitation exposes the entire Chamilo LMS database, including student personally identifiable information (PII), teacher credentials, financial and course data, and system configurations (GitHub Advisory). By chaining the SQL injection with the predictable password reset mechanism, an attacker can achieve full administrative account takeover, enabling unauthorized modification of course content, user management, and platform configuration. This represents a complete compromise of confidentiality and integrity for all data hosted on the affected LMS instance, with significant risk to educational institutions and their users.

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of active in-the-wild exploitation (Feedly). The vulnerability has an EPSS score of approximately 0.00143, indicating a currently low but non-negligible probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time. However, the unauthenticated nature and critical severity make it a high-priority target for opportunistic attackers scanning for vulnerable Chamilo instances.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Chamilo LMS instances running versions ≤ 1.11.32 using search engines like Shodan or Censys, or by fingerprinting the application via HTTP response headers and login page content.
  2. Locate the vulnerable parameter: Identify the endpoint that processes the custom_dates parameter — this is accessible without authentication.
  3. Inject SQL payload: Craft a malicious HTTP request containing SQL injection syntax in the custom_dates parameter (e.g., using time-based blind or UNION-based techniques) to enumerate the database schema and extract data such as user credentials and password reset tokens.
  4. Exploit predictable password reset: Using data extracted from the database (e.g., reset tokens or user account details), leverage Chamilo's legacy password reset mechanism — which uses a predictable token generation algorithm — to trigger a password reset for an administrator account.
  5. Account takeover: Submit the predicted or extracted reset token to set a new administrator password, gaining full administrative access to the Chamilo LMS platform without any prior credentials (GitHub Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to Chamilo endpoints containing the custom_dates parameter with SQL metacharacters (e.g., single quotes, UNION, SELECT, SLEEP, WAITFOR) in the query string or POST body; unexpected outbound database query traffic.
  • Logs: Web server access logs showing anomalous requests to Chamilo pages with encoded or obfuscated SQL syntax in the custom_dates parameter; repeated password reset requests for administrator accounts from unknown IP addresses; authentication events for admin accounts from unfamiliar IPs or at unusual times.
  • Application: Unexpected changes to administrator account passwords or email addresses; new administrator accounts created without authorization; modifications to course content, user roles, or system configuration settings.
  • Database: Evidence of large-scale SELECT queries or data dumps in database query logs; queries targeting sensitive tables such as user credentials, PII, or session tokens.

Mitigation and workarounds

The vendor has released a patch in Chamilo LMS version 1.11.34, which is described as primarily a security release addressing this and related issues (GitHub Release). Version 2.0 is also listed as a patched version (GitHub Advisory). All organizations running Chamilo LMS versions ≤ 1.11.32 should upgrade to version 1.11.34 or later immediately. As an interim measure, restricting network access to the Chamilo instance (e.g., via firewall rules or WAF rules blocking SQL injection patterns in the custom_dates parameter) can reduce exposure until patching is complete.

Community reactions

The vulnerability was noted across multiple vulnerability tracking platforms and security community feeds shortly after disclosure, including VulDB, CIRCL, and INCIBE-CERT (Feedly). A brief write-up was published by Infinit Security highlighting the unauthenticated SQL injection in Chamilo LMS. The Mastodon/infosec.exchange community also referenced the advisory. No major vendor statements beyond the official GitHub Security Advisory have been issued, and media coverage has been limited to vulnerability aggregator sites.

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management