The Hacker Wire@TheHackerWireDisclosure
Chamilo LMS 1.11.36‑pre versions have a high‑severity arbitrary file upload flaw in the H5P Import feature that permits authenticated Teacher users to deploy potentially malicious files.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text publicly discloses an RCE vulnerability (CVE-2026-30875) in the Chamilo LMS H5P import feature prior to version 1.11.36, listing technical details but providing no PoC, exploit, patch, or evidence of active exploitation.
CVE@CVEnewDisclosure
Chamilo LMS versions before 1.11.36 are vulnerable to an arbitrary file upload via the H5P Import feature; the issue is resolved in v1.11.36, with no PoC or active exploitation reported.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
An alert reports CVE‑2026‑30875, indicating an authenticated remote‑code‑execution vulnerability via H5P Import in Chamilo LMS, with a link to an Intel Report but no exploitation details or patch information.
CVEFind.com@CveFindComPatch
The post announces a critical RCE vulnerability in Chamilo LMS and directs users to update to version 1.11.36 to mitigate the issue.