Tag
high
advisory
Chamilo LMS Path Traversal Vulnerability (CVE-2026-31939)
2 rules 1 TTP 1 CVEA path traversal vulnerability (CVE-2026-31939) in Chamilo LMS versions prior to 1.11.38 allows authenticated attackers to delete arbitrary files via unsanitized user input in the 'test' parameter of savescores.php.
path-traversal
file-deletion
chamilo-lms
2r
1t
1c
critical
advisory
Chamilo LMS OS Command Injection Vulnerability (CVE-2026-35196)
2 rules 1 TTP 1 CVEChamilo LMS versions prior to 2.0.0-RC.3 are vulnerable to OS Command Injection via the _cid session variable in the export_all_certificates action, potentially leading to arbitrary command execution.
PoC
cve-2026-35196
os command injection
chamilo lms
web application
2r
1t
1c
updated