Executive brief
Chamilo LMS, a popular open-source learning management system, contains a security flaw in its exercise sound upload feature. An authorized user with teacher-level permissions can upload malicious files, such as a web shell, by tricking the system into believing the file is an audio or video clip. This allows an attacker to take full control of the web server, potentially leading to the theft of student data, exposure of database credentials, or a complete service outage.
Technical details
An unrestricted file upload vulnerability exists in the `Exercise::updateSound()` method within `main/exercise/exercise.class.php`. The application validates uploaded files solely by checking the client-provided `Content-Type` header for the strings 'audio' or 'video', which can be easily spoofed. Because the system fails to verify file extensions or magic bytes and uses the unsanitized original filename, an attacker with teacher privileges can upload a PHP file (e.g., shell.php) to a web-accessible directory. This results in Remote Code Execution (RCE) as the web server user. The vulnerability also allows for potential path traversal due to the lack of filename sanitization. The issue is resolved in versions 1.11.38 and 2.0.0-RC.3 by removing the unused vulnerable method.
Affected products
- Chamilo Chamilo LMS < 1.11.38, < 2.0.0-RC.3
Timeline
- 2026-04-10: advisory: Vendor advisory and CVE published
- 2026-04-10: patched: Fixes committed to GitHub repository