CVE-2025-50194: Chamilo: OS Command Injection in /main/cron/lang/check_parse_lang.php
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/cron/lang/checkparselang.php. This issue has been patched in version 1.11.30.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50194?
CVE-2025-50194 is classified as a critical severity vulnerability due to its potential for OS command injection.
How do I fix CVE-2025-50194?
To fix CVE-2025-50194, upgrade Chamilo to version 1.11.30 or later where the vulnerability has been patched.
What is affected by CVE-2025-50194?
CVE-2025-50194 affects Chamilo versions prior to 1.11.30, specifically the file /main/cron/lang/check_parse_lang.php.
What could an attacker do exploiting CVE-2025-50194?
An attacker exploiting CVE-2025-50194 could execute arbitrary OS commands, potentially compromising the system.
Is there a workaround for CVE-2025-50194?
There are no recommended workarounds for CVE-2025-50194; the best mitigation is to upgrade to the fixed version.