SQL Injection Vulnerability in Chamilo Learning Management System
CVE-2025-50190
8.8HIGH
What is CVE-2025-50190?
The Chamilo Learning Management System is susceptible to an error-based SQL Injection vulnerability that can be exploited via the GET parameter openid.assoc_handle in the /index.php script. This flaw allows attackers to manipulate database queries, which could lead to unauthorized access or the leakage of sensitive data. The vulnerability was addressed in version 1.11.30, and users are urged to upgrade to this version or later to mitigate potential security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
chamilo-lms < 1.11.30
