Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move function. The move() function in fileManage.lib.php passes user-controlled path values directly into exec() shell commands without using escapeshellarg(). When a user moves a document via document.php, the move_to POST parameter — which only passes through Security::remove_XSS() (an HTML-only filter) — is concatenated directly into shell commands such as exec("mv $source $target"). By default, Chamilo allows all authenticated users to create courses (allow_users_to_create_courses = true). Any user who is a teacher in a course (including self-created courses) can move documents, making this vulnerability exploitable by any authenticated user. The attacker must first place a directory with shell metacharacters in its name on the filesystem (achievable via Course Backup Import), then move a document into that directory to trigger arbitrary command execution as the web server user (www-data). This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.
The move() function in fileManage.lib.php passes user-controlled path values directly to shell commands executed by exec() without using escapeshellarg(). The POST parameter move_to is only filtered through Security::remove_XSS(), which removes only HTML tags without neutralizing shell metacharacters. The attacker must first place a directory containing shell metacharacters in its name on the server (possible through the course backup import function), then move a document into it — causing concatenation of the malicious path name into the exec("mv $source $target") command and thus executing arbitrary code. Default Chamilo configuration allows all authenticated users to create courses, making the required teacher context achievable by any logged-in user.
An attacker can execute arbitrary system commands in the context of the web server user (www-data), which may lead to complete server takeover, data breach, and compromise of other systems accessible from the server.
Update Chamilo LMS to version 1.11.38 or later (1.x branch) or to version 2.0.0-RC.3 or later (2.x branch). Patches are available in vendor references: commit 3597b19b73d73d681e4fb503285e9bbfe71714bf and commit 62671e5e268f235cddfba704edee90f35c234df1. Additionally, as a remedial measure, consider disabling course creation by regular users (allow_users_to_create_courses = false) and restricting access to the course backup import function.
Chamilo LMS in versions earlier than 1.11.38 (1.x branch) and earlier than 2.0.0-RC.3 (2.x branch)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HChamilo Lms
APPChamilo2.0.0< 1.11.38
Related vulnerabilities
Chamilo LMS — przewidywalny token resetowania hasła (CWE-640)
Chamilo LMS: ominięcie uwierzytelnienia i modyfikacja plików przez katalog install
Niezauwytoryzowany SQL injection w Chamilo LMS — przejęcie konta administratora
Stored XSS w Chamilo LMS — przejęcie kont wyżej uprzywilejowanych użytkowników
Stored XSS w Chamilo LMS umożliwiający przejęcie kont administratorów