CVE-2026-30881: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2026-30881 is a SQL Injection vulnerability in Chamilo LMS affecting versions 1.11.34 and prior. The flaw resides in the statistics AJAX endpoint (main/inc/ajax/statistics.ajax.php), where the date_start and date_end parameters from $_REQUEST are embedded directly into raw SQL queries without effective sanitization. It was reported on 2026-03-06, published on 2026-03-16, and patched in version 1.11.36 released on 2026-03-08. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Feedly).

Technical details

The root cause (CWE-89) involves two compounding flaws: unsanitized user input in main/inc/ajax/statistics.ajax.php (lines 254–259) where $_REQUEST['date_start'] and $_REQUEST['date_end'] are concatenated directly into an SQL fragment, and a broken escape mechanism in main/inc/lib/usermanager.lib.php (line 2346) where Database::escape_string() escapes single quotes to \', but an immediately following str_replace("\', "'", ...)call reverts the escaping entirely. A UI-layerSecurity::remove_XSS()call inmain/admin/statistics/index.php` only strips HTML/script tags and provides no SQL injection protection. The attack vector is network-based, requires low privileges (any authenticated user with admin role), and enables blind time-based and conditional SQL data extraction (GitHub Advisory).

Impact

Successful exploitation allows an authenticated attacker to inject arbitrary SQL statements into the Chamilo LMS database, enabling unauthorized extraction of sensitive data (user credentials, course records, personal information), modification of database records, and potential disruption of database availability. The vulnerability has HIGH impact on confidentiality, integrity, and availability. Depending on database server configuration, exploitation could potentially be escalated to operating system command execution via SQL features such as INTO OUTFILE or stored procedures (GitHub Advisory, Feedly).

Exploitability

As of the time of disclosure, no public proof-of-concept exploit code has been identified and there is no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.03%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authentication with an admin role, which limits the attack surface compared to unauthenticated vulnerabilities.

Exploitation steps

  1. Reconnaissance: Identify Chamilo LMS instances running version 1.11.34 or earlier using web search, Shodan, or Censys queries targeting Chamilo-specific paths or headers.
  2. Authentication: Obtain valid admin-level credentials through phishing, credential stuffing, or other means, then authenticate to the Chamilo LMS instance.
  3. Locate the vulnerable endpoint: Navigate to or directly target the statistics AJAX endpoint at main/inc/ajax/statistics.ajax.php, which accepts date_start and date_end parameters via $_REQUEST.
  4. Craft the SQL injection payload: Inject a time-based blind SQL payload into the date_start or date_end parameter, e.g., date_start=2024-01-01' AND SLEEP(5)-- -. Because str_replace("\'", "'", ...) undoes the escaping, the injected single quote survives into the SQL query.
  5. Enumerate the database: Use tools such as sqlmap with the authenticated session cookie against the vulnerable endpoint to automate blind time-based extraction of database schema, user tables, and credential hashes.
  6. Exfiltrate data: Extract sensitive records (user credentials, personal data, course information) from the database using conditional or time-based inference techniques (GitHub Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to main/inc/ajax/statistics.ajax.php with date_start or date_end parameters containing SQL keywords (SLEEP, AND, OR, SELECT, UNION, --) or encoded variants; abnormally high response times on requests to the statistics endpoint suggesting time-based blind injection.
  • Logs: Web server access logs showing requests to the statistics AJAX endpoint with malformed or SQL-like date parameter values; repeated requests with slight parameter variations consistent with automated SQL enumeration tools like sqlmap.
  • Process: Unusual database query patterns in MySQL slow query logs, particularly queries with SLEEP() calls or deeply nested conditional expressions originating from the Chamilo application user.

Mitigation and workarounds

The primary remediation is to upgrade Chamilo LMS to version 1.11.36 or later, which was released as a security-focused update on 2026-03-08 (GitHub Release). For environments where immediate patching is not feasible, restrict access to the statistics AJAX endpoint (main/inc/ajax/statistics.ajax.php) to trusted IP ranges or administrative networks only, and monitor for SQL-like patterns in request parameters. Long-term, the codebase should be refactored to use parameterized queries or prepared statements for all user-supplied input, and the broken escape pattern (str_replace("\'", "'", Database::escape_string(...))) should be removed (GitHub Advisory).

Community reactions

The vulnerability was covered by The Hacker Wire, which published a dedicated technical write-up on the SQL injection flaw (The Hacker Wire). The advisory was assigned by GitHub Security (GitHub_M) and tracked by ENISA under EUVD-2026-12500. Community reaction has been moderate, with the vulnerability indexed across multiple threat intelligence aggregators including VulDB, CVEFeed, and Wiz Vulnerability Database shortly after disclosure.

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management