Chamilo LMS GitHub Repositoryproduct
https://github.com/chamilo/chamilo-lms CVE-2018-25158
HIGH
Chamilo LMS 1.11.8 Arbitrary File Upload via elfinder
Record summary
CVE-2018-25158 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute PHP files through the elfinder filemanager module. Attackers can upload files with image headers in the social myfiles section, rename them to PHP extensions, and execute arbitrary code by accessing the uploaded files.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 24, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Chamillo LMSBrowse Chamilo / Chamillo LMS | CVE List | Chamilo 1.11.8 or lower to 1.8 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBChamillo LMS 1.11.8 - Arbitrary File UploadExploitDB exploitby Sohel YousefNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-25158 ExploitDB-47423exploit
https://www.exploit-db.com/exploits/47423 VulnCheck Advisory: Chamilo LMS 1.11.8 Arbitrary File Upload via elfinderThird-party advisory
https://www.vulncheck.com/advisories/chamilo-lms-arbitrary-file-upload-via-elfinder