Chamilo LMS is a learning management system. Prior to version 1.11.36, an arbitrary file upload vulnerability in the H5P Import feature allows authenticated users with Teacher role to achieve Remote Code Execution (RCE). The H5P package validation only checks if h5p.json exists but doesn't block .htaccess or PHP files with alternative extensions. An attacker uploads a crafted H5P package containing a webshell and .htaccess that enables PHP execution for .txt files, bypassing security control. This issue has been patched in version 1.11.36.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:* |
Tue, 17 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chamilo
Chamilo chamilo Lms |
|
| Vendors & Products |
Chamilo
Chamilo chamilo Lms |
Mon, 16 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Chamilo LMS is a learning management system. Prior to version 1.11.36, an arbitrary file upload vulnerability in the H5P Import feature allows authenticated users with Teacher role to achieve Remote Code Execution (RCE). The H5P package validation only checks if h5p.json exists but doesn't block .htaccess or PHP files with alternative extensions. An attacker uploads a crafted H5P package containing a webshell and .htaccess that enables PHP execution for .txt files, bypassing security control. This issue has been patched in version 1.11.36. | |
| Title | Chamilo LMS: Authenticated RCE via H5P Import | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-16T19:16:37.936Z
Updated: 2026-03-16T20:22:42.979Z
Reserved: 2026-03-06T00:04:56.699Z
Link: CVE-2026-30875
Updated: 2026-03-16T20:20:32.838Z
Status : Analyzed
Published: 2026-03-16T20:16:18.330
Modified: 2026-03-17T18:53:29.480
Link: CVE-2026-30875
No data.
ReportizFlow