Vendor
Chamilo LMS CStudio Unauthenticated Remote Code Execution
1 rule 2 TTPs 1 CVEAn unauthenticated remote code execution vulnerability in the Chamilo LMS CStudio upload flow allows attackers to gain server-level access by exploiting improper file handling (CVE-2026-45140).
Chamilo LMS Unrestricted File Upload Leads to Remote Code Execution
2 rules 1 TTP 1 CVEAn unrestricted file upload vulnerability in Chamilo LMS (CVE-2026-32931) allows an authenticated teacher to upload a PHP webshell, leading to remote code execution.
Chamilo LMS OS Command Injection Vulnerability (CVE-2026-35196)
2 rules 1 TTP 1 CVEChamilo LMS versions prior to 2.0.0-RC.3 are vulnerable to OS Command Injection via the _cid session variable in the export_all_certificates action, potentially leading to arbitrary command execution.
Chamilo LMS Remote Code Execution via Arbitrary File Upload (CVE-2026-33704)
2 rules 1 TTP 1 CVEChamilo LMS versions prior to 1.11.38 are vulnerable to remote code execution via arbitrary file upload by authenticated users due to insufficient file extension filtering in the BigUpload endpoint, allowing execution of PHP code on servers configured to process .pht files.