No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 24 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chamilo
Chamilo chamilo Lms |
|
| Vendors & Products |
Chamilo
Chamilo chamilo Lms |
Fri, 20 Feb 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute PHP files through the elfinder filemanager module. Attackers can upload files with image headers in the social myfiles section, rename them to PHP extensions, and execute arbitrary code by accessing the uploaded files. | |
| Title | Chamilo LMS 1.11.8 Arbitrary File Upload via elfinder | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-24T15:20:59.316Z
Reserved: 2026-02-12T14:34:47.030Z
Link: CVE-2018-25158
Updated: 2026-02-24T15:20:55.400Z
Status : Awaiting Analysis
Published: 2026-02-20T23:15:59.373
Modified: 2026-02-23T18:14:13.887
Link: CVE-2018-25158
No data.
OpenCVE Enrichment
Updated: 2026-02-23T14:33:29Z