CVE-2025-50192: Chamilo: Time-based SQL Injection in /main/webservices/registration.soap.php
Published Mar 2, 2026
·Updated
Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main/webservices/registration.soap.php. This issue has been patched in version 1.11.30.
Affected Software
2 affected components
Chamilo Chamilo<1.11.30
Chamilo Chamilo LMS<1.11.30
Remediation
Event History
Mar 2, 2026
CVE Published
via MITRE·02:54 PM
Data Sourced
via MITRE·02:54 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-50192?
CVE-2025-50192 has a critical severity rating due to its impact on data integrity and potential exploitation through time-based SQL injection.
2
How do I fix CVE-2025-50192?
To fix CVE-2025-50192, upgrade Chamilo to version 1.11.30 or later.
3
What versions of Chamilo are affected by CVE-2025-50192?
CVE-2025-50192 affects all versions of Chamilo prior to 1.11.30.
4
What is the nature of the vulnerability in CVE-2025-50192?
CVE-2025-50192 is a time-based SQL injection vulnerability located in the /main/webservices/registration.soap.php file.
5
When was CVE-2025-50192 discovered?
CVE-2025-50192 was discovered prior to the release of the patch in September 2023.