{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/chamilo-lms--2.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-45140"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=5BD031A7-1596-56B4-A7CD-0362166F2282\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Chamilo LMS (\u003c= 2.0.0)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","web-application","critical-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Chamilo"],"content_html":"\u003cp\u003eChamilo LMS versions 2.0.0 and earlier are vulnerable to an unauthenticated remote code execution (RCE) flaw in the CStudio file upload component. The vulnerability, tracked as CVE-2026-45140, stems from a combination of path traversal (CWE-22) and unrestricted file upload (CWE-434) issues. Attackers can leverage the upload flow to store malicious files within the web document root, which can subsequently be executed by the server. This allows for total compromise of the application and potentially the underlying server infrastructure. Given the lack of required privileges and user interaction, this vulnerability represents a critical risk for deployments of Chamilo LMS. Users are strongly advised to upgrade to version 2.0.1 or later to remediate the flaw.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to full server compromise, allowing unauthenticated attackers to execute arbitrary code, modify application data, and access sensitive files. The vulnerability affects all Chamilo LMS instances running version 2.0.0 or older. Given the high CVSS score of 9.8, the potential for data exfiltration and complete system takeover is high for affected organizations in the education and corporate learning sectors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Chamilo LMS installations to version 2.0.1 or later immediately to patch CVE-2026-45140.\u003c/li\u003e\n\u003cli\u003eAudit webserver access logs for POST requests to the CStudio upload endpoint followed by direct requests to unusual files in the application's upload directory.\u003c/li\u003e\n\u003cli\u003eImplement strict ingress filtering for web traffic to the application to minimize exposure to unauthenticated exploitation attempts.\u003c/li\u003e\n\u003cli\u003eReview file system permissions on the web root to ensure that user-uploaded content directories do not have execution privileges.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T19:45:20Z","date_published":"2026-09-18T01:10:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-chamilo-rce/","summary":"An unauthenticated remote code execution vulnerability in the Chamilo LMS CStudio upload flow allows attackers to gain server-level access by exploiting improper file handling (CVE-2026-45140).","title":"Chamilo LMS CStudio Unauthenticated Remote Code Execution","url":"https://feed.craftedsignal.io/briefs/2026-09-chamilo-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Chamilo LMS (\u003c= 2.0.0)","version":"https://jsonfeed.org/version/1.1"}