Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a remote code execution (RCE) within versions 1.11.12 to 1.11.26. By abusing multiple supported features from the virtualization plugin vchamilo, the vulnerability allows an administrator to execute arbitrary code on the server. This issue has been patched in version 1.11.26.
References
| Link | Resource |
|---|---|
| https://github.com/chamilo/chamilo-lms/releases/tag/v1.11.28 | Product Release Notes |
| https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-c4fc-vjm9-9mvc | Exploit Vendor Advisory |
Configurations
History
03 Mar 2026, 19:11
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
| References | () https://github.com/chamilo/chamilo-lms/releases/tag/v1.11.28 - Product, Release Notes | |
| References | () https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-c4fc-vjm9-9mvc - Exploit, Vendor Advisory | |
| First Time |
Chamilo chamilo Lms
Chamilo |
02 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-02 15:16
Updated : 2026-03-03 19:11
NVD link : CVE-2024-47886
Mitre link : CVE-2024-47886
CVE.ORG link : CVE-2024-47886
JSON object : View
Products Affected
chamilo
- chamilo_lms
CWE
CWE-502
Deserialization of Untrusted Data
