PT-2026-95083 · Unknown · Chamilo Lms
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Chamilo LMS versions prior to 2.0.1
Description
Chamilo LMS, an open-source learning management system, contains a flaw that allows an unauthenticated remote attacker to execute arbitrary code directly on the server. The authoritative advisory does not identify the specific affected endpoint, component, input, or exploitation mechanism.
Recommendations
Update Chamilo LMS to version 2.0.1.
Restrict access to the LMS interface to trusted internal networks or require VPN authentication.
Review web server access logs for unusual POST requests or script execution attempts in uploads/plugins directories.
Exploit
Fix
RCE
Path traversal
Code Injection
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Chamilo Lms