CRITICAL🇵🇱 Wersja polska

CVE-2026-33698

CVSS 9.3v4.0pub. 2026-04-10upd. 2026-04-16

Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated attacker to modify existing files or create new files where allowed by system permissions. This only affects portals with the main/install/ directory still present and read-accessible. This vulnerability is fixed in 1.11.38.

🤖 AI Analysis
How it works

The attack involves chaining improper file access control (CWE-552), allowing unlocking and execution of PHP code located in the main/install/ directory, which should be inaccessible after installation is complete. An unauthenticated attacker can use this technique to modify existing files or create new files in locations permitted by system permissions. The success of the attack requires the presence and accessibility of the main/install/ directory on the target server.

Impact

An unauthenticated attacker can modify existing application files or create new files on the server, which could lead to complete takeover of the application, including deployment of malicious code.

Mitigation & patch

Update Chamilo LMS to version 1.11.38 or newer. Regardless of the update, it is recommended to remove or block access to the main/install/ directory after completing the system installation process.

Who is affected

Chamilo LMS in versions earlier than 1.11.38, only installations with the main/install/ directory accessible for reading.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Chamilo Lms

    APP
    Chamilo
    < 1.11.38
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-33707CRITICAL9.4PL ✓same product

Chamilo LMS — przewidywalny token resetowania hasła (CWE-640)

CVE-2026-32892CRITICAL9.1PL ✓same product

OS Command Injection w Chamilo LMS — funkcja przenoszenia plików

CVE-2026-28430CRITICAL9.3PL ✓same product

Niezauwytoryzowany SQL injection w Chamilo LMS — przejęcie konta administratora

CVE-2025-59542CRITICAL9.0PL ✓same product

Stored XSS w Chamilo LMS — przejęcie kont wyżej uprzywilejowanych użytkowników

CVE-2025-59543CRITICAL9.0PL ✓same product

Stored XSS w Chamilo LMS umożliwiający przejęcie kont administratorów