Impact
Chamilo Learning Management System is vulnerable to unauthenticated remote code execution as disclosed in advisory for versions prior to 2.0.1. The breach is facilitated through the CStudio upload flow, enabling an attacker to upload malicious code that is subsequently interpreted by the server. The issue combines several weaknesses – unsafe file handling (CWE‑434), directory traversal (CWE‑22), improper file permissions (CWE‑219), and potential code injection (CWE‑94) – and is rated with a CVSS score of 9.8, indicating a critical level of risk. Successful exploitation results in full compromise of the web server, allowing attackers to execute arbitrary code and potentially pivot to other systems.
Affected Systems
The affected product is Chamilo LMS supplied by the chamilo:chamilo-lms vendor. All installations running a version older than 2.0.1 are impacted. The advisory does not specify a target sub‑version or release build, so any deploys of the open‑source LMS that have not applied the 2.0.1 patch release are considered vulnerable.
Risk and Exploitability
The CVSS score of 9.8 signals a severe vulnerability, though the EPSS value of less than 1% indicates a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, meaning no confirmed widespread exploitation has been reported. The attack vector is likely unauthenticated via the web; a remote attacker can submit a crafted upload request to the CStudio flow, bypass authentication checks, and trigger code execution. Because the advisory notes a lack of endpoint or mechanism detail, any deployment exposing the upload functionality to the internet is at risk, and the lack of defensive measures in the affected code snapshot makes exploitation straightforward for determined adversaries.
OpenCVE Enrichment
Github GHSA