
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30875 is an arbitrary file upload vulnerability in the H5P Import feature of Chamilo LMS that allows authenticated users with the Teacher role to achieve Remote Code Execution (RCE). It affects Chamilo LMS versions prior to 1.11.36 (specifically confirmed in version 1.11.34 and earlier). The vulnerability was published on March 16, 2026, and patched in version 1.11.36 released on March 8, 2026. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Feedly).
The root cause is improper control of code generation (CWE-94) stemming from insufficient validation in the H5P package import process. The H5P package validator only checks for the presence of h5p.json but does not block the inclusion of .htaccess files or PHP webshells using alternative extensions (e.g., .txt). An attacker crafts a malicious H5P .zip package containing a PHP webshell renamed with an innocuous extension (e.g., shell.txt) and a .htaccess file that instructs Apache to execute .txt files as PHP, then uploads it via the H5P Import feature. Once the package is extracted to a web-accessible directory, the attacker can request the webshell URL directly to execute arbitrary server-side commands (GitHub Advisory).
Successful exploitation results in full server compromise under the web server process account (typically www-data), with high impact to confidentiality, integrity, and availability. An attacker can read, modify, or delete any files accessible to the web server, extract database credentials from configuration files, and use the compromised server as a pivot point for lateral movement within the network. No user interaction is required beyond the initial upload by the authenticated teacher-role attacker (GitHub Advisory, Feedly).
As of the time of reporting, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.169%, indicating a currently low probability of exploitation in the near term. Exploitation requires a valid Teacher-role account, which limits the attack surface to authenticated users but does not require administrative privileges.
.h5p extension containing at minimum: a valid h5p.json file (to pass validation), a PHP webshell saved with an alternative extension (e.g., shell.txt containing <?php system($_GET['cmd']); ?>), and a .htaccess file with the directive AddType application/x-httpd-php .txt to enable PHP execution for .txt files..h5p package.app/upload/h5p/content/ or similar).https://target/app/upload/h5p/content/<id>/shell.txt?cmd=id) to execute arbitrary OS commands as the www-data user.cmd=, exec=, or similar shell command indicators..htaccess files within H5P upload/content directories (e.g., app/upload/h5p/content/) containing AddType application/x-httpd-php; unexpected .txt, .jpg, or other non-PHP files in H5P content directories containing PHP code (<?php)..txt, .jpg) within H5P content paths returning HTTP 200 with PHP-generated output; Chamilo application logs showing H5P package imports by Teacher-role accounts followed immediately by requests to the extracted content directory.apache2, nginx) such as bash, sh, curl, wget, python, or nc (GitHub Advisory).The primary remediation is to upgrade Chamilo LMS to version 1.11.36 or later, which patches the H5P import validation to block .htaccess files and PHP files with alternative extensions (GitHub Release). As an interim workaround for organizations unable to upgrade immediately: restrict H5P Import functionality to only highly trusted users, implement server-level configuration to prevent .htaccess overrides in upload directories (AllowOverride None), and deploy WAF rules to detect and block malicious H5P package uploads. Monitor web server logs for suspicious PHP execution patterns in H5P content directories.
The vulnerability was reported by security researchers DhiyaneshGeek and neo-ai-engineer and disclosed via GitHub Security Advisories on March 15, 2026 (GitHub Advisory). Coverage appeared on The Hacker Wire and yazoul.net shortly after disclosure, and the vulnerability was indexed by multiple threat intelligence platforms including VulDB, CIRCL, and Wiz. Community reaction has been moderate, consistent with the authenticated-only attack vector limiting immediate widespread concern.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."