CVE-2025-50199Disclosure(chamilo / chamilo_lms)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch chamilo chamilo_lms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via the POST openid_url parameter. This issue has been patched in version 1.11.30.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chamilo_lms

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-03-02); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
chamilo_lms

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-03-02: 1Mentions · 2026-03-03: 1Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Patch / Workaround · 2026-03-03: 1Technical Details · 2026-03-02: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 103-0203-0303-0503-0603-07
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-021
Disclosure1
2026-03-031
Disclosure1
2026-03-051
Disclosure1
2026-03-061
Disclosure1
2026-03-071
General1
Full discourse5 posts
  • CRAC Learning - Tech@cracbot
    General

    CVE-2025-50199 (CVSS:7.7, CRITICAL) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via..https://nvd.nist.gov/vuln/detail/CVE-2025-50199 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post highlights a critical blind SSRF flaw in Chamilo older than 1.11.30, citing NVD details, but it provides no PoC, exploit code, patch information, or evidence of active exploitation.

    00000110
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-50199 (CVSS:7.7, CRITICAL) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via..https://nvd.nist.gov/vuln/detail/CVE-2025-50199 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet highlights a blind SSRF vulnerability (CVE-2025-50199) in Chamilo prior to version 1.11.30, providing technical details like CVSS score but no PoC, exploit, patch, or evidence of active exploitation.

    0000048
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-50199 (CVSS:7.7, CRITICAL) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via..https://nvd.nist.gov/vuln/detail/CVE-2025-50199 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post discloses a blind SSRF vulnerability (CVE‑2025‑50199) affecting Chamilo versions before 1.11.30, with a CVSS score of 7.7 (CRITICAL). No exploit, patch, or active exploitation details are provided.

    0000039
    173 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-50199 - Critical Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via the POST openid_url parameter. This issue has been patched in vers... https://www.thehackerwire.com/vulnerability/CVE-2025-50199/ https://t.co/cOzR5oVb22

    Post summary

    CVE‑2025‑50199 is a blind SSRF vulnerability in Chamilo (prior to 1.11.30), which has been patched; no PoC or active exploitation details are provided.

    00000124
    121 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-50199 - Chamilo: Blind Server-Side Request Forgery (Unauth Blind SSRF) Intel Report: https://ift.tt/Ws2Klex

    Post summary

    An alert announces CVE-2025-50199, a blind SSRF vulnerability in Chamilo, with no evidence of exploitation or patch information provided.

    00000102
    342 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchamilochamilo_lms---

Explore more