Remote Code Execution Vulnerability in Chamilo Learning Management System
CVE-2025-50187
9.8CRITICAL
What is CVE-2025-50187?
Chamilo Learning Management System, prior to version 1.11.28, contains a vulnerability where parameters received from SOAP requests are evaluated without proper filtering. This oversight can allow an attacker to execute arbitrary code remotely, posing a significant security risk. The issue has been addressed in version 1.11.28, which includes necessary patches to mitigate this vulnerability.
Affected Version(s)
chamilo-lms < 1.11.28
