CRITICAL🇵🇱 Wersja polska

CVE-2026-32892

CVSS 9.1v3.1pub. 2026-04-10upd. 2026-04-17

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move function. The move() function in fileManage.lib.php passes user-controlled path values directly into exec() shell commands without using escapeshellarg(). When a user moves a document via document.php, the move_to POST parameter — which only passes through Security::remove_XSS() (an HTML-only filter) — is concatenated directly into shell commands such as exec("mv $source $target"). By default, Chamilo allows all authenticated users to create courses (allow_users_to_create_courses = true). Any user who is a teacher in a course (including self-created courses) can move documents, making this vulnerability exploitable by any authenticated user. The attacker must first place a directory with shell metacharacters in its name on the filesystem (achievable via Course Backup Import), then move a document into that directory to trigger arbitrary command execution as the web server user (www-data). This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.

🤖 AI Analysis
How it works

The move() function in fileManage.lib.php passes user-controlled path values directly to shell commands executed by exec() without using escapeshellarg(). The POST parameter move_to is only filtered through Security::remove_XSS(), which removes only HTML tags without neutralizing shell metacharacters. The attacker must first place a directory containing shell metacharacters in its name on the server (possible through the course backup import function), then move a document into it — causing concatenation of the malicious path name into the exec("mv $source $target") command and thus executing arbitrary code. Default Chamilo configuration allows all authenticated users to create courses, making the required teacher context achievable by any logged-in user.

Impact

An attacker can execute arbitrary system commands in the context of the web server user (www-data), which may lead to complete server takeover, data breach, and compromise of other systems accessible from the server.

Mitigation & patch

Update Chamilo LMS to version 1.11.38 or later (1.x branch) or to version 2.0.0-RC.3 or later (2.x branch). Patches are available in vendor references: commit 3597b19b73d73d681e4fb503285e9bbfe71714bf and commit 62671e5e268f235cddfba704edee90f35c234df1. Additionally, as a remedial measure, consider disabling course creation by regular users (allow_users_to_create_courses = false) and restricting access to the course backup import function.

Who is affected

Chamilo LMS in versions earlier than 1.11.38 (1.x branch) and earlier than 2.0.0-RC.3 (2.x branch)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Chamilo Lms

    APP
    Chamilo
    2.0.0< 1.11.38
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSSCommand Injection
CWE
References

Related vulnerabilities

CVE-2026-33707CRITICAL9.4PL ✓same product

Chamilo LMS — przewidywalny token resetowania hasła (CWE-640)

CVE-2026-33698CRITICAL9.3PL ✓same product

Chamilo LMS: ominięcie uwierzytelnienia i modyfikacja plików przez katalog install

CVE-2026-28430CRITICAL9.3PL ✓same product

Niezauwytoryzowany SQL injection w Chamilo LMS — przejęcie konta administratora

CVE-2025-59542CRITICAL9.0PL ✓same product

Stored XSS w Chamilo LMS — przejęcie kont wyżej uprzywilejowanych użytkowników

CVE-2025-59543CRITICAL9.0PL ✓same product

Stored XSS w Chamilo LMS umożliwiający przejęcie kont administratorów