CVE-2025-50193: Chamilo: OS command Injection in /plugin/vchamilo/views/import.php with the POST to_main_database parameter
Published Mar 2, 2026
·Updated
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS command Injection vulnerability in /plugin/vchamilo/views/import.php with the POST tomaindatabase parameter. This issue has been patched in version 1.11.30.
Affected Software
2 affected components
Chamilo Chamilo<1.11.30
Chamilo Chamilo LMS<1.11.30
Remediation
Event History
Mar 2, 2026
CVE Published
via MITRE·03:16 PM
Data Sourced
via MITRE·03:16 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-50193?
CVE-2025-50193 is classified as a critical severity vulnerability due to its potential for OS command injection.
2
How do I fix CVE-2025-50193?
To fix CVE-2025-50193, upgrade Chamilo to version 1.11.30 or later as it resolves the vulnerability.
3
Which versions of Chamilo are affected by CVE-2025-50193?
CVE-2025-50193 affects all versions of Chamilo prior to 1.11.30.
4
What is the impact of CVE-2025-50193?
The impact of CVE-2025-50193 allows an attacker to execute arbitrary OS commands on the server.
5
Is CVE-2025-50193 specific to any features in Chamilo?
Yes, CVE-2025-50193 specifically affects the import functionality accessed via the /plugin/vchamilo/views/import.php endpoint.