Chamilo is a learning management system. Prior to version 1.11.30, Chamilo is vulnerable to deserialization of untrusted data in /plugin/vchamilo/views/import.php via POST configuration_file; POST course_path; POST home_path parameters. This issue has been patched in version 1.11.30.
References
Configurations
History
No history.
Information
Published : 2026-03-02 16:16
Updated : 2026-03-03 19:42
NVD link : CVE-2025-50198
Mitre link : CVE-2025-50198
CVE.ORG link : CVE-2025-50198
JSON object : View
Products Affected
chamilo
- chamilo_lms
CWE
CWE-502
Deserialization of Untrusted Data
