CVE-2025-50189Disclosure(chamilo / chamilo_lms)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch chamilo chamilo_lms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the POST resource[document][SQL_INJECTION_HERE] and POST login parameters found in /main/coursecopy/copy_course_session_selected.php, which allows an attacker to perform an attack aimed at modifying the database query logic by injecting an arbitrary SQL statements. This issue has been patched in version 1.11.30.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chamilo_lms

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • Peaked 5d ago at 3 mentions (2026-03-02); latest day: 1
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
chamilo_lms

Deep dive

Activity timeline8 mentions / 6d
01223Mentions · 2026-03-02: 3Mentions · 2026-03-03: 1Mentions · 2026-03-04: 1Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Patch / Workaround · 2026-03-03: 1Technical Details · 2026-03-02: 3Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 103-0203-0303-0403-0503-0603-07
Signal classification2 categories
Disclosure
787.5%
Patch
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-023
Disclosure3
2026-03-031
Patch1
2026-03-041
Disclosure1
2026-03-051
Disclosure1
2026-03-061
Disclosure1
2026-03-071
Disclosure1
Full discourse8 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-50189 (CVSS:7.2, HIGH) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of d..https://nvd.nist.gov/vuln/detail/CVE-2025-50189 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE-2025-50189 in Chamilo with a CVSS score of 7.2 and references its analysis on the NVD, but it provides no PoC, exploit code, or patch information.

    0000096
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-50189 (CVSS:7.2, HIGH) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of d..https://nvd.nist.gov/vuln/detail/CVE-2025-50189 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet points to CVE‑2025‑50189, noting its CVSS score and a validation weakness in Chamilo versions before 1.11.30, but it provides no PoC, exploit code, or patch info.

    0000039
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-50189 (CVSS:7.2, HIGH) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of d..https://nvd.nist.gov/vuln/detail/CVE-2025-50189 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2025‑50189, a High‑severity flaw (CVSS 7.2) in Chamilo due to insufficient input validation in versions prior to 1.11.30, and links to the NVD page.

    0000024
    173 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-50189 - High Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the POST resource[document][SQL_INJECTION... https://www.thehackerwire.com/vulnerability/CVE-2025-50189/ https://t.co/nbps6AB1M9

    Post summary

    Chamilo LMS is vulnerable to SQL injection due to insufficient input validation before version 1.11.30. No PoC, exploit, or patch details are provided in the text.

    0000076
    121 followersView on X
  • Fernando Karl@fernandokarl
    Patch

    🚨 Atenção, equipes de TI! Chamilo LMS <1.11.30 apresenta uma vulnerabilidade crítica de SQL Injection. Atualize para a versão 1.11.30 e proteja seus dados! 🔒 Quais medidas você está tomando para garantir a segurança? #Cybersecurity #SQLInjection https://www.tenable.com/cve/CVE-2025-50189

    Post summary

    The post alerts IT teams to a critical SQL injection flaw in Chamilo LMS versions below 1.11.30 and urges users to update to version 1.11.30 to protect their data.

    00000104
    255 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-50189 SQL Injection Vulnerability in Chamilo LMS Before Version 1.11.30 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-50189

    Post summary

    The text announces a SQL injection vulnerability in Chamilo LMS versions prior to 1.11.30, identified as CVE-2025-50189, with no additional details on exploitation or mitigation.

    0000073
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-50189 Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the POST resourc… https://www.cve.org/CVERecord?id=CVE-2025-50189 ----- Traducción: CVE-2025-50189 Cha… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2025‑50189, noting insufficient POST data validation in Chamilo before v1.11.30, but provides no PoC, exploit, or patch details.

    0000086
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-50189 Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the POST resourc… https://www.cve.org/CVERecord?id=CVE-2025-50189

    Post summary

    The snippet announces CVE-2025-50189 in Chamilo LMS, noting insufficient POST data validation before v1.11.30, but provides no PoC, exploit, or patch details.

    00000172
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchamilochamilo_lms---

Explore more