Junglewise Threat Intelligence

CVE-2026-31939: Chamilo LMS path traversal in savescores.php

CVE-2026-31939 · Severity: high · CVSS 8.3 · Published 2026-04-10

Technologies: Chamilo Lms. Vendors: Chamilo.

Executive brief

Chamilo LMS is an open-source learning management system used by educational institutions and businesses to deliver online training. A security flaw in the system's exercise scoring component allows an authenticated user to delete arbitrary files from the server. This could lead to significant data loss, system instability, or the removal of critical security files, potentially disrupting educational operations and requiring manual restoration from backups.

Technical details

A path traversal vulnerability exists in Chamilo LMS versions 1.11.36 and prior within the 'main/exercise/savescores.php' script. The application fails to sanitize the 'test' request parameter, which is directly concatenated into a file path used by the 'my_delete()' function. An authenticated attacker with low privileges (such as a student or course participant) can use '../' sequences to traverse outside the intended directory and delete arbitrary files that the web server has permissions to modify. The root cause is a lack of path canonicalization and boundary checks. The issue is resolved in version 1.11.38 by implementing realpath() validation and ensuring the target path resides within the expected base directory.

Affected products

  • Chamilo Chamilo LMS <= 1.11.36

Timeline

  • 2026-03-24: patched: Version 1.11.38 released
  • 2026-04-10: disclosed: Vendor advisory published via GitHub
  • 2026-04-10: advisory: CVE-2026-31939 assigned

References

Related threats