CVE-2025-50195: Chamilo: OS Command Injection in /plugin/vchamilo/views/manage.controller.php
Published Mar 2, 2026
·Updated
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/manage.controller.php. This issue has been patched in version 1.11.30.
Affected Software
2 affected components
Chamilo Chamilo<1.11.30
Chamilo Chamilo LMS<1.11.30
Remediation
Event History
Mar 2, 2026
CVE Published
via MITRE·03:16 PM
Data Sourced
via MITRE·03:16 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-50195?
CVE-2025-50195 has high severity due to the potential for OS Command Injection, which can lead to unauthorized command execution on the server.
2
How do I fix CVE-2025-50195?
To fix CVE-2025-50195, upgrade your Chamilo installation to version 1.11.30 or later.
3
What is the affected software for CVE-2025-50195?
CVE-2025-50195 affects Chamilo prior to version 1.11.30.
4
What type of vulnerability is CVE-2025-50195?
CVE-2025-50195 is classified as an OS Command Injection vulnerability.
5
Is there a patch available for CVE-2025-50195?
Yes, a patch for CVE-2025-50195 was released with Chamilo version 1.11.30.