CVE-2025-50191

Publication date

2026-03-02 14:53:36

Family

GitHub_M

State

PUBLISHED

Description

Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via POST userFile with the /main/exercise/hotpotatoes.php script. This issue has been patched in version 1.11.30.