← back
CVE-2025-50197highCWE-78

Chamilo: OS Command Injection in /main/admin/sub_language_ajax.inc.php via POST new_language parameter

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.1epss 2.7%
exploitation probability
2.7%top 16% of all CVEs
observed exploitation
nono source reports it
In short

Chamilo, a learning management system, has a vulnerability that allows attackers to run dangerous system commands on the server through the language settings page. This happens because user input is not properly checked before being executed.

Technical detail

OS command injection vulnerability in /main/admin/sub_language_ajax.inc.php where the POST parameter 'new_language' is passed unsanitized to system command execution. An authenticated attacker can inject shell metacharacters to achieve remote code execution with server privileges. Patched in version 1.11.30.

Summary generated and translated by AI from the official description.
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/admin/sub_language_ajax.inc.php via the POST new_language parameter. This issue has been patched in version 1.11.30.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
chamilo · chamilo-lms