Back to Database
Status published
Critical
CVE-2025-50187
Chamilo: Evaluation of untrusted user input leads to Remote Code Execution
Vulnerability Description
Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filtering which leads to Remote Code Execution. This issue has been patched in version 1.11.28.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-50187
Credits & Attribution
No credits recorded in the NVD database.
References
More from chamilo
View All →CVE-2025-66447
Chamilo LMS has validation-less redirect on login page
Unknown
0
CVE-2025-59544
Chamilo: Unauthorized access to update category of any user
Medium
6.9
CVE-2025-59543
Chamilo: Account Takeover via Stored XSS in Course Description
Critical
9.1
CVE-2025-59542
Chamilo: Account Takeover via Stored XSS in Course Learning Paths
Critical
9.1
CVE-2025-59541
Chamilo: CSRF Vulnerability in Project Deletion
High
8.1
Affected Vendor
chamilo
View all reports →Affected Software
chamilo-lms
Vulnerable Versions:
< 1.11.28
Timeline
Official Publish:
March 2nd, 2026
Last Modified:
March 2nd, 2026
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.