CVE-2025-50190Disclosure(chamilo / chamilo_lms)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch chamilo chamilo_lms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET openid.assoc_handle parameter with the /index.php script. This issue has been patched in version 1.11.30.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chamilo_lms

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 3 mentions (2026-03-02); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
chamilo_lms

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-03-02: 3Mentions · 2026-03-04: 1Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Patch / Workaround · 2026-03-04: 1Technical Details · 2026-03-02: 3Technical Details · 2026-03-04: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 103-0203-0403-0503-0603-07
Signal classification2 categories
Disclosure
685.7%
General
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-023
Disclosure2General1
2026-03-041
Disclosure1
2026-03-051
Disclosure1
2026-03-061
Disclosure1
2026-03-071
Disclosure1
Full discourse7 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-50190 (CVSS:8.8, CRITICAL) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET ope..https://nvd.nist.gov/vuln/detail/CVE-2025-50190 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE‑2025‑50190, a critical error‑based SQL injection in Chamilo prior to version 1.11.30, but offers no exploitation or patch details.

    0000097
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-50190 (CVSS:8.8, CRITICAL) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET ope..https://nvd.nist.gov/vuln/detail/CVE-2025-50190 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post highlights CVE-2025‑50190 as a critical error‑based SQL injection in Chamilo before v1.11.30, referencing the NVD entry, without mentioning PoC, exploit, or patch.

    0000039
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-50190 (CVSS:8.8, CRITICAL) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET ope..https://nvd.nist.gov/vuln/detail/CVE-2025-50190 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2025‑50190, a critical error‑based SQL injection in Chamilo releases before v1.11.30, offering technical details but lacking PoC, exploit code, active‑attack evidence, or patch information.

    0000032
    173 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-50190 - Critical Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET openid.assoc_handle parameter with the /index.php script. This issue h... https://www.thehackerwire.com/vulnerability/CVE-2025-50190/ https://t.co/YIusJODyE3

    Post summary

    Chamilo LMS allows error-based SQL injection through the openid.assoc_handle GET parameter before version 1.11.30, and a patch is implied by the version threshold.

    0000086
    121 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-50190 SQL Injection Vulnerability in Chamilo Learning Management System Pre-1.11.30 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-50190

    Post summary

    A SQL injection vulnerability (CVE-2025-50190) has been identified in Chamilo Learning Management System versions prior to 1.11.30.

    0000074
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-50190 Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET openid.assoc_handle parameter with the /index.php… https://www.cve.org/CVERecord?id=CVE-2025-50190 ----- Traducción: CVE-2025-50190 Cha… http://infoflow.cloud`

    Post summary

    The post announces CVE-2025-50190, an error-based SQL injection in Chamilo before version 1.11.30 via the openid.assoc_handle GET parameter, and provides a link to the CVE record.

    0000086
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-50190 Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET openid.assoc_handle parameter with the /index.php… https://www.cve.org/CVERecord?id=CVE-2025-50190

    Post summary

    The post announces an error‑based SQL injection vulnerability in Chamilo (pre‑v1.11.30) affecting the openid.assoc_handle parameter, but provides no PoC, exploitation evidence, or patch information.

    00000176
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchamilochamilo_lms---

Explore more