Chamilo LMS versions prior to 1.11.38 contain a critical chained attack vulnerability that allows unauthenticated attackers to execute PHP code from the main/install/ directory and modify or create arbitrary files on affected systems. The vulnerability only impacts installations where the main/install/ directory remains present and read-accessible, making proper post-deployment cleanup essential for mitigation. The vulnerability carries a CVSS score of 9.8 (CRITICAL) with a network-based attack vector requiring no authentication, user interaction, or elevated privileges. The attack has low complexity and can result in complete compromise of confidentiality, integrity, and availability across the entire system. There is currently no evidence of active exploitation in the wild, and the vulnerability does not appear on the KEV or Hot List catalogs. The EPSS score of 0.00084 indicates relatively low probability of exploitation compared to other published vulnerabilities, suggesting the threat landscape impact remains limited despite the critical severity rating. Organizations should prioritize upgrades to version 1.11.38 or later and verify removal of the main/install/ directory as a preventive measure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.11.38CPE matchmatch criteria | cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.