CVE-2025-50196: Chamilo: OS Command Injection in /plugin/vchamilo/views/editinstance.php via POST main_database parameter
Published Mar 2, 2026
·Updated
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/editinstance.php via the POST maindatabase parameter. This issue has been patched in version 1.11.30.
Affected Software
2 affected components
Chamilo Chamilo<1.11.30
Chamilo Chamilo LMS<1.11.30
Remediation
Event History
Mar 2, 2026
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-50196?
CVE-2025-50196 is considered a high severity vulnerability due to its potential for OS Command Injection.
2
How do I fix CVE-2025-50196?
To fix CVE-2025-50196, upgrade Chamilo to version 1.11.30 or later.
3
What is affected by CVE-2025-50196?
CVE-2025-50196 affects Chamilo versions prior to 1.11.30.
4
What is OS Command Injection in CVE-2025-50196?
OS Command Injection in CVE-2025-50196 allows an attacker to execute arbitrary commands on the server.
5
Where is the vulnerability located in CVE-2025-50196?
The vulnerability is located in /plugin/vchamilo/views/editinstance.php via the POST main_database parameter.