Arbitrary File Upload Vulnerability in Chamilo LMS by Chamilo
CVE-2026-30875
What is CVE-2026-30875?
Chamilo LMS, a popular learning management system, has a vulnerability in the H5P Import feature that permits authenticated teachers to perform arbitrary file uploads. This security flaw arises because the system's validation process only verifies the presence of a h5p.json file, neglecting to block the upload of malicious .htaccess or PHP files under different extensions. By crafting a specific H5P package, an attacker can upload a webshell that alters PHP execution permissions for text files, leading to potential remote code execution. This issue has been addressed in version 1.11.36 of Chamilo LMS.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
chamilo-lms < 1.11.36
