CVE detail
CVE-2025-50188 — CVE-2025-50188
Published 2026-03-02 · Modified 2026-06-17 · Vendor chamilo · Product chamilo_lms · Source nvd
HIGH
severity
CVSS-derived band
0.0071
EPSS probability
exploitation probability, 30d
50.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the GET value parameter with the following scripts: /plugin/vchamilo/views/syncparams.php and /plugin/vchamilo/ajax/service.php, which allows an attacker to perform an attack aimed at modifying the database query logic by injecting an arbitrary SQL statements. This issue has been patched in version 1.11.30.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References