CVE-2025-52998Disclosure(chamilo / chamilo_lms)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is performed, the data can be spoofed. An attacker can create objects of arbitrary classes, as well as fully control their properties, and thus modify the logic of the web application's operation. This issue has been patched in version 1.11.30.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chamilo_lms

Threat summary

  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-03-02); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
chamilo_lms

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-03-02: 1Mentions · 2026-03-03: 1Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Technical Details · 2026-03-02: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 103-0203-0303-0503-0603-07
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-021
Disclosure1
2026-03-031
Disclosure1
2026-03-051
Disclosure1
2026-03-061
General1
2026-03-071
Disclosure1
Full discourse5 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-52998 (CVSS:7.0, CRITICAL) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is perfor..https://nvd.nist.gov/vuln/detail/CVE-2025-52998 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post highlights CVE‑2025‑52998 as a critical deserialization vulnerability in Chamilo (pre‑1.11.30) and links to its NVD entry, but does not provide a PoC, exploit, or patch information.

    00000118
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2025-52998 (CVSS:7.0, CRITICAL) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is perfor..https://nvd.nist.gov/vuln/detail/CVE-2025-52998 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2025‑52998, noting its CVSS score and that it involves deserialization vulnerabilities in Chamilo prior to v1.11.30, but offers no further technical detail, exploit code, or patch information.

    0000053
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-52998 (CVSS:7.0, CRITICAL) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is perfor..https://nvd.nist.gov/vuln/detail/CVE-2025-52998 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet reports the analysis of CVE-2025-52998, giving its CVSS score and describing a deserialization flaw in Chamilo, but does not mention any PoC, exploit, active use, or patch.

    0000038
    173 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-52998 - Critical Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is performed, the data can be spoofed. An attacker can create objects of arb... https://www.thehackerwire.com/vulnerability/CVE-2025-52998/ https://t.co/HUGlWedDSD

    Post summary

    The post reports a critical deserialization vulnerability in Chamilo (CVE‑2025‑52998) that could enable arbitrary object creation, but it does not include PoC, exploit, or patch details.

    00000117
    121 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-52998 - Chamilo: PHAR deserialization bypass Intel Report: https://ift.tt/ldoGuNr

    Post summary

    Alert announces CVE-2025-52998, a PHAR deserialization bypass in Chamilo, with an Intel Report link but no PoC, exploit, or patch details.

    0000096
    342 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchamilochamilo_lms---

Explore more