GHSA-g4c3-4g96-6g4m: Path Traversal
Published Sep 17, 2026
·Updated
Impact Ability to run arbitrary code on the server without authentication.
Affected Software
1 affected componentFixes available
composer/chamilo/chamilo-lms<=2.0.0
2.0.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/chamilo/chamilo-lmsto a version that resolves this vulnerability.Fixed in 2.0.1
Event History
Sep 17, 2026
Advisory Published
via GitHub·08:23 PM
Data Sourced
via GitHub·08:23 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The issue is remotely exploitable over the network and requires no authentication, privileges, or user interaction.
2
What impact should responders assume if exploitation succeeds?
An attacker can run arbitrary code on the affected server. The CVSS vector rates confidentiality, integrity, and availability impact as high.