Record summary

CVE-2018-25158 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.

Description

Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute PHP files through the elfinder filemanager module. Attackers can upload files with image headers in the social myfiles section, rename them to PHP extensions, and execute arbitrary code by accessing the uploaded files.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 24, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListChamilo 1.11.8 or lower to 1.8affected

Proofs of concept

1

Catalogued exploits

ExploitDBChamillo LMS 1.11.8 - Arbitrary File UploadExploitDB exploitby Sohel YousefNot analyzed1 file
ExploitDB

PoC details

References

4