CVE-2025-50187 is a critical Remote Code Execution (RCE) vulnerability affecting Chamilo Learning Management System versions prior to 1.11.28. The flaw, categorized as CWE-95, stems from unfiltered parameter evaluation within SOAP requests, allowing unauthenticated attackers to execute arbitrary code. With a CVSS score of 9.8, this vulnerability presents a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered some community discussion, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.11.28CPE matchmatch criteria | cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.