CVE-2026-30875: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2026-30875 is an arbitrary file upload vulnerability in the H5P Import feature of Chamilo LMS that allows authenticated users with the Teacher role to achieve Remote Code Execution (RCE). It affects Chamilo LMS versions prior to 1.11.36 (specifically confirmed in version 1.11.34 and earlier). The vulnerability was published on March 16, 2026, and patched in version 1.11.36 released on March 8, 2026. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Feedly).

Technical details

The root cause is improper control of code generation (CWE-94) stemming from insufficient validation in the H5P package import process. The H5P package validator only checks for the presence of h5p.json but does not block the inclusion of .htaccess files or PHP webshells using alternative extensions (e.g., .txt). An attacker crafts a malicious H5P .zip package containing a PHP webshell renamed with an innocuous extension (e.g., shell.txt) and a .htaccess file that instructs Apache to execute .txt files as PHP, then uploads it via the H5P Import feature. Once the package is extracted to a web-accessible directory, the attacker can request the webshell URL directly to execute arbitrary server-side commands (GitHub Advisory).

Impact

Successful exploitation results in full server compromise under the web server process account (typically www-data), with high impact to confidentiality, integrity, and availability. An attacker can read, modify, or delete any files accessible to the web server, extract database credentials from configuration files, and use the compromised server as a pivot point for lateral movement within the network. No user interaction is required beyond the initial upload by the authenticated teacher-role attacker (GitHub Advisory, Feedly).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.169%, indicating a currently low probability of exploitation in the near term. Exploitation requires a valid Teacher-role account, which limits the attack surface to authenticated users but does not require administrative privileges.

Exploitation steps

  1. Obtain Teacher credentials: Acquire a valid Chamilo LMS account with the Teacher role through registration, phishing, credential stuffing, or social engineering.
  2. Craft malicious H5P package: Create a ZIP archive with the .h5p extension containing at minimum: a valid h5p.json file (to pass validation), a PHP webshell saved with an alternative extension (e.g., shell.txt containing <?php system($_GET['cmd']); ?>), and a .htaccess file with the directive AddType application/x-httpd-php .txt to enable PHP execution for .txt files.
  3. Upload via H5P Import: Log in to Chamilo LMS, navigate to the H5P content import feature (typically under course content management), and upload the crafted .h5p package.
  4. Locate extracted files: Identify the web-accessible path where H5P packages are extracted (commonly under app/upload/h5p/content/ or similar).
  5. Execute webshell: Send an HTTP GET request to the webshell URL (e.g., https://target/app/upload/h5p/content/<id>/shell.txt?cmd=id) to execute arbitrary OS commands as the www-data user.
  6. Escalate and persist: Use the webshell to establish a reverse shell, extract database credentials from Chamilo configuration files, and perform further lateral movement or data exfiltration (GitHub Advisory).

Indicators of compromise

  • Network: Unusual outbound connections from the web server process to external IPs (potential reverse shell callbacks); HTTP requests to H5P content directories with query parameters like cmd=, exec=, or similar shell command indicators.
  • File System: Presence of .htaccess files within H5P upload/content directories (e.g., app/upload/h5p/content/) containing AddType application/x-httpd-php; unexpected .txt, .jpg, or other non-PHP files in H5P content directories containing PHP code (<?php).
  • Logs: Web server access logs showing GET/POST requests to files with non-PHP extensions (.txt, .jpg) within H5P content paths returning HTTP 200 with PHP-generated output; Chamilo application logs showing H5P package imports by Teacher-role accounts followed immediately by requests to the extracted content directory.
  • Process: Unusual child processes spawned by the web server (e.g., apache2, nginx) such as bash, sh, curl, wget, python, or nc (GitHub Advisory).

Mitigation and workarounds

The primary remediation is to upgrade Chamilo LMS to version 1.11.36 or later, which patches the H5P import validation to block .htaccess files and PHP files with alternative extensions (GitHub Release). As an interim workaround for organizations unable to upgrade immediately: restrict H5P Import functionality to only highly trusted users, implement server-level configuration to prevent .htaccess overrides in upload directories (AllowOverride None), and deploy WAF rules to detect and block malicious H5P package uploads. Monitor web server logs for suspicious PHP execution patterns in H5P content directories.

Community reactions

The vulnerability was reported by security researchers DhiyaneshGeek and neo-ai-engineer and disclosed via GitHub Security Advisories on March 15, 2026 (GitHub Advisory). Coverage appeared on The Hacker Wire and yazoul.net shortly after disclosure, and the vulnerability was indexed by multiple threat intelligence platforms including VulDB, CIRCL, and Wiz. Community reaction has been moderate, consistent with the authenticated-only attack vector limiting immediate widespread concern.

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management