CVE-2025-50196 | Chamilo LMS up to 1.11.29 editinstance.php main_database os command injection (EUVD-2025-208165)
A vulnerability, which was classified as critical, has been found in Chamilo LMS up to 1.11.29. The impacted element is an unknown function of the file /plugin/vchamilo/views/editinstance.php. The manipulation of the argument main_database leads to os command injection.
This vulnerability is uniquely identified as CVE-2025-50196. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.