PT-2026-32013 · Unknown · Chamilo Lms
CVE-2026-33618
·
Published
2026-04-10
·
Updated
2026-04-11
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Chamilo LMS versions prior to 2.0.0-RC.3
Description
Chamilo LMS, a learning management system, has an issue where the
PlatformConfigurationController::decodeSettingArray() method uses PHP's eval() function to process platform settings retrieved from the database. An attacker with administrator privileges can inject arbitrary PHP code into these settings. This injected code is then executed when any user, even unauthenticated ones, accesses the '/platform-config/list' API endpoint. This allows for remote code execution.Recommendations
Upgrade to version 2.0.0-RC.3 or later.
Exploit
Fix
RCE
Eval Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chamilo Lms