Chamilo LMS CStudio upload flow allows unauthenticated remote code execution
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.8epss 1.0%
from disclosure to weapon1 days
Published on NVDSep 17
1st PoC+1d
exploitation probability
1.0%top 40% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, component, input, or exploitation mechanism. This issue is fixed in version 2.0.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
chamilo · chamilo-lmspublic PoCs found — 1
githubgithub.com/abraxas/CVE-2026-45140★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.