Skip to content
COOEY

FAIL › dossier

chamilo

VENDOR

· dossier confidence 20%

Chamilo is an open-source LMS that suffered critical remote code execution vulnerabilities in 2023 due to unvalidated inputs in core components like SOAP APIs and file upload handlers.

PROFILE
CategoryLMS VendorWhat they doChamilo is an open-source Learning Management System (LMS) used for educational institutions and corporate training. Websitehttps://www.chamilo.org ↗
SECURITY POSTURE

The vendor has a critical security posture characterized by severe, unpatched command injection and arbitrary file upload vulnerabilities in core components, indicating a lack of rigorous input validation and secure coding practices.

Notable failures
  • CVE-2023-34960 RCE via SOAP API
  • CVE-2023-34944 Arbitrary File Upload RCE
Patterns: critical RCEs in core components; lack of input validation in SOAP/API endpoints
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2023-08-01 CVE-2023-34960 critical A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.
2023-08-01 CVE-2023-34960 critical A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.
2023-06-13 CVE-2023-34944 critical An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file.
Open questions: Chamilo's exact founding date and headquarters location · Chamilo's current patch response time for critical vulnerabilities
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-20 19:12:39.634779+00:00