CVE-2025-50187
CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filtering which leads to Remote Code Execution. This issue has been patched in version 1.11.28.
Metadata
Severity & Metrics
9.8
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| chamilo | chamilo-lms | — | < 1.11.28 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-95 | cna | CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.8 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
References (2)
- https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-356v-7xg2-3678 https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-356v-7xg2-3678
- https://github.com/chamilo/chamilo-lms/releases/tag/v1.11.28 https://github.com/chamilo/chamilo-lms/releases/tag/v1.11.28