CVE-2025-50188Disclosure(chamilo / chamilo_lms)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the GET value parameter with the following scripts: /plugin/vchamilo/views/syncparams.php and /plugin/vchamilo/ajax/service.php, which allows an attacker to perform an attack aimed at modifying the database query logic by injecting an arbitrary SQL statements. This issue has been patched in version 1.11.30.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chamilo_lms

Threat summary

  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-03-02); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
chamilo_lms

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-02: 3Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Technical Details · 2026-03-02: 2Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 103-0203-0503-0603-07
Signal classification2 categories
Disclosure
583.3%
General
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-023
Disclosure2General1
2026-03-051
Disclosure1
2026-03-061
Disclosure1
2026-03-071
Disclosure1
Full discourse6 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-50188 (CVSS:7.0, HIGH) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of d..https://nvd.nist.gov/vuln/detail/CVE-2025-50188 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces that CVE‑2025‑50188 has been analyzed, gives its CVSS score, and notes that Chamilo versions prior to 1.11.30 lack proper validation, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000094
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-50188 (CVSS:7.0, HIGH) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of d..https://nvd.nist.gov/vuln/detail/CVE-2025-50188 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post reports that CVE‑2025‑50188, assessed as CVSS 7.0 HIGH, affects Chamilo LMS versions older than 1.11.30 due to insufficient input validation, but it does not provide a PoC, exploit, or patch information.

    0000038
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-50188 (CVSS:7.0, HIGH) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of d..https://nvd.nist.gov/vuln/detail/CVE-2025-50188 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces analysis of CVE‑2025‑50188 with a CVSS of 7.0, noting that Chamilo versions before 1.11.30 have insufficient input validation, but provides no PoC, exploit, patch, or detailed technical description.

    0000026
    173 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-50188 SQL Injection Vulnerability in Chamilo Learning Management System Before 1.11.30 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-50188

    Post summary

    A SQL injection vulnerability (CVE-2025-50188) exists in Chamilo Learning Management System versions prior to 1.11.30, with no further exploitation or mitigation details provided.

    0000070
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-50188 Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the GET value pa… https://www.cve.org/CVERecord?id=CVE-2025-50188 ----- Traducción: CVE-2025-50188 Cha… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2025‑50188, noting insufficient validation of GET parameters in Chamilo before v1.11.30, but provides no PoC, exploit, or patch details.

    0000086
    55 followersView on X
  • CVE@CVEnew
    General

    CVE-2025-50188 Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the GET value pa… https://www.cve.org/CVERecord?id=CVE-2025-50188

    Post summary

    The snippet references CVE‑2025‑50188 in Chamilo LMS, noting insufficient GET parameter validation before v1.11.30, but offers no further details or actionable information.

    00000178
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchamilochamilo_lms---

Explore more