CVE-2025-50198: Chamilo: Deserialization of untrusted data in /plugin/vchamilo/views/import.php via POST configuration_file; POST course_path; POST home_path parameters
Chamilo is a learning management system. Prior to version 1.11.30, Chamilo is vulnerable to deserialization of untrusted data in /plugin/vchamilo/views/import.php via POST configurationfile; POST coursepath; POST homepath parameters. This issue has been patched in version 1.11.30.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50198?
CVE-2025-50198 is classified as a high-severity vulnerability due to the potential exploitation of deserialization of untrusted data.
How do I fix CVE-2025-50198?
To fix CVE-2025-50198, upgrade Chamilo to version 1.11.30 or later, which addresses this vulnerability.
What impact does CVE-2025-50198 have on Chamilo?
CVE-2025-50198 allows attackers to exploit untrusted data deserialization, potentially leading to remote code execution.
What components of Chamilo are affected by CVE-2025-50198?
CVE-2025-50198 affects the /plugin/vchamilo/views/import.php file, specifically through the POST parameters configuration_file, course_path, and home_path.
Can I still use Chamilo if it's vulnerable to CVE-2025-50198?
While it is possible to use an affected version, it is highly recommended to upgrade to avoid the risks associated with CVE-2025-50198.