CVE-2025-50193 - CVE House
Back to Database
Status published High CVE-2025-50193

Chamilo: OS command Injection in /plugin/vchamilo/views/import.php with the POST to_main_database parameter

Vulnerability Description

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS command Injection vulnerability in /plugin/vchamilo/views/import.php with the POST to_main_database parameter. This issue has been patched in version 1.11.30.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-50193

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

chamilo-lms
Vulnerable Versions:
< 1.11.30

Timeline

Official Publish: March 2nd, 2026
Last Modified: March 2nd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)