Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/chamilo/chamilo-lms

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax.php path. This endpoint is protected only by `api_protect_course_script(true)`, which means any authenticated user enrolled in a course (student, teacher, DRH) can reach it.

Join the discussion

Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser session, leading to full platform admin account takeover. This has been patched in 1.11.40.

Join the discussion

Chamilo LMS versions prior to 2.0.0-RC.3 contain an improper privilege management vulnerability in the PUT /api/users/{id} endpoint. Authenticated users with the ROLE_STUDENT can escalate their privileges to ROLE_ADMIN by modifying the roles field on their own user record. This is due to insufficient authorization checks and the roles field being writable. Exploitation grants full administrative control over the platform, including access to all courses, user data, grades, and administrative settings. The vulnerability has been fixed in version 2.0.0-RC.

Join the discussion

Chamilo LMS versions prior to 2.0.0-RC.3 contain an OS Command Injection vulnerability in the gradebook.ajax.php endpoint. The vulnerability arises because the course code from the session variable is directly concatenated into a shell_exec() command without proper sanitization. An attacker able to manipulate session data can inject shell metacharacters, leading to arbitrary command execution on the server. This can result in full system compromise, including reading sensitive files, altering the application or database, and disrupting server availability. The issue is fixed in version 2.

Join the discussion

Chamilo LMS versions prior to 2.0.0-RC.3 contain an authorization bypass vulnerability in the /api/course_rel_users endpoint. An authenticated attacker can manipulate the user parameter to enroll arbitrary users into courses without proper authorization. This occurs because the backend does not verify ownership or permission for the user ID supplied. The vulnerability allows unauthorized access to course materials and compromises enrollment controls. The issue is fixed in version 2.0.0-RC.

Join the discussion

Chamilo LMS versions prior to 2.0.0-RC.3 contain an Insecure Direct Object Reference (IDOR) vulnerability in the notebook module. This flaw allows any authenticated student to access private course notes of other users by manipulating the notebook_id parameter in the editnote action. The application does not verify ownership when reading notes, exposing the full title and HTML content to unauthorized users. Ownership checks exist only for updating or deleting notes, not for reading them. This vulnerability has been fixed in version 2.0.0-RC.

Join the discussion

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the social post attachment upload functionality, where an authenticated user can upload a malicious HTML file containing JavaScript via the /api/social_post_attachments endpoint. The uploaded file is served back from the application at the generated contentUrl without sanitization, content type restrictions, or a Content-Disposition: attachment header, causing the JavaScript to execute in the browser within the application's origin. Because the payload is stored server-side and runs in the trusted origin, an attacker can perform session hijacking, account takeover, privilege escalation (if an admin views the link), and arbitrary actions on behalf of the victim. This issue has been fixed in version 2.0.0-RC.3.

Join the discussion

Chamilo LMS versions prior to 2.0.0-RC.3 contain an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the PENS plugin endpoint. This endpoint accepts a user-controlled URL parameter that the server fetches without filtering internal or private IP addresses. Exploitation allows attackers to probe internal network services, access cloud metadata endpoints to steal credentials, or trigger state-changing operations on internal services without authentication. The issue has been fixed in version 2.0.0-RC.3.

Join the discussion

Chamilo LMS version 2.0-RC.2 contains a vulnerability where a critical AJAX endpoint (install.ajax.php) is accessible without authentication. This endpoint's test_mailer action accepts arbitrary SMTP server details from unauthenticated POST requests, enabling Server-Side Request Forgery (SSRF) and abuse as an open email relay. This can lead to phishing and spam campaigns originating from the server and may disclose internal network information through error messages. The issue is fixed in version 2.0.0-RC.

Join the discussion

Chamilo LMS version 2.0.0-RC.2 contains a SQL Injection vulnerability in the statistics AJAX endpoint. This vulnerability is due to incomplete sanitization of the date_start and date_end parameters in the users_active action, allowing an authenticated admin to perform time-based blind SQL injection. The issue was fixed in version 2.0.0. The vulnerability has a CVSS score of 7.1, indicating high severity.

Join the discussion

Showing 1 to 10 of 78 results

Filters:Package: pkg:github/chamilo/chamilo-lms
Page 1 of 8
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses