← back
CVE-2025-50187criticalCWE-95

Chamilo: Evaluation of untrusted user input leads to Remote Code Execution

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 0.9%
exploitation probability
0.9%top 44% of all CVEs
observed exploitation
nono source reports it
In short

Chamilo learning platform allows attackers to run arbitrary code on the server by sending specially crafted SOAP requests with unfiltered commands. This is critical because attackers can take complete control of the system and steal or destroy all educational data.

Technical detail

CWE-95 code injection vulnerability in Chamilo's SOAP request handler prior to v1.11.28 allows unauthenticated remote code execution via unsanitized parameter evaluation. Attack vector is network-based through SOAP endpoints; no authentication required. Successful exploitation grants arbitrary code execution with server privileges, enabling full system compromise.

Summary generated and translated by AI from the official description.
Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filtering which leads to Remote Code Execution. This issue has been patched in version 1.11.28.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
chamilo · chamilo-lms