
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30881 is a SQL Injection vulnerability in Chamilo LMS affecting versions 1.11.34 and prior. The flaw resides in the statistics AJAX endpoint (main/inc/ajax/statistics.ajax.php), where the date_start and date_end parameters from $_REQUEST are embedded directly into raw SQL queries without effective sanitization. It was reported on 2026-03-06, published on 2026-03-16, and patched in version 1.11.36 released on 2026-03-08. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Feedly).
The root cause (CWE-89) involves two compounding flaws: unsanitized user input in main/inc/ajax/statistics.ajax.php (lines 254–259) where $_REQUEST['date_start'] and $_REQUEST['date_end'] are concatenated directly into an SQL fragment, and a broken escape mechanism in main/inc/lib/usermanager.lib.php (line 2346) where Database::escape_string() escapes single quotes to \', but an immediately following str_replace("\', "'", ...)call reverts the escaping entirely. A UI-layerSecurity::remove_XSS()call inmain/admin/statistics/index.php` only strips HTML/script tags and provides no SQL injection protection. The attack vector is network-based, requires low privileges (any authenticated user with admin role), and enables blind time-based and conditional SQL data extraction (GitHub Advisory).
Successful exploitation allows an authenticated attacker to inject arbitrary SQL statements into the Chamilo LMS database, enabling unauthorized extraction of sensitive data (user credentials, course records, personal information), modification of database records, and potential disruption of database availability. The vulnerability has HIGH impact on confidentiality, integrity, and availability. Depending on database server configuration, exploitation could potentially be escalated to operating system command execution via SQL features such as INTO OUTFILE or stored procedures (GitHub Advisory, Feedly).
As of the time of disclosure, no public proof-of-concept exploit code has been identified and there is no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.03%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authentication with an admin role, which limits the attack surface compared to unauthenticated vulnerabilities.
main/inc/ajax/statistics.ajax.php, which accepts date_start and date_end parameters via $_REQUEST.date_start or date_end parameter, e.g., date_start=2024-01-01' AND SLEEP(5)-- -. Because str_replace("\'", "'", ...) undoes the escaping, the injected single quote survives into the SQL query.sqlmap with the authenticated session cookie against the vulnerable endpoint to automate blind time-based extraction of database schema, user tables, and credential hashes.main/inc/ajax/statistics.ajax.php with date_start or date_end parameters containing SQL keywords (SLEEP, AND, OR, SELECT, UNION, --) or encoded variants; abnormally high response times on requests to the statistics endpoint suggesting time-based blind injection.sqlmap.SLEEP() calls or deeply nested conditional expressions originating from the Chamilo application user.The primary remediation is to upgrade Chamilo LMS to version 1.11.36 or later, which was released as a security-focused update on 2026-03-08 (GitHub Release). For environments where immediate patching is not feasible, restrict access to the statistics AJAX endpoint (main/inc/ajax/statistics.ajax.php) to trusted IP ranges or administrative networks only, and monitor for SQL-like patterns in request parameters. Long-term, the codebase should be refactored to use parameterized queries or prepared statements for all user-supplied input, and the broken escape pattern (str_replace("\'", "'", Database::escape_string(...))) should be removed (GitHub Advisory).
The vulnerability was covered by The Hacker Wire, which published a dedicated technical write-up on the SQL injection flaw (The Hacker Wire). The advisory was assigned by GitHub Security (GitHub_M) and tracked by ENISA under EUVD-2026-12500. Community reaction has been moderate, with the vulnerability indexed across multiple threat intelligence aggregators including VulDB, CVEFeed, and Wiz Vulnerability Database shortly after disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."