Chamilo LMS versions prior to 1.11.38 and 2.0.0-RC.3 contain an OS command injection vulnerability in the document move functionality. The flaw exists in fileManage.lib.php where user-controlled path values are passed directly to exec() shell commands without proper sanitization, allowing arbitrary command execution as the web server user. The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring only low privileges and no user interaction. Any authenticated user who can create or teach a course can exploit this by moving documents into specially crafted directory names containing shell metacharacters, leading to complete compromise of confidentiality, integrity, and availability. This vulnerability is not currently tracked in the CISA Known Exploited Vulnerabilities catalog and shows minimal community attention with an EPSS score of 0.00117, indicating low exploitation probability. No public exploit code appears to be readily available, though the attack requires only authenticated access and basic technical knowledge to execute successfully.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.11.38CPE matchmatch criteria | cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha1:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha2:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha3:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha4:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.