CVE-2025-50198 | Chamilo LMS up to 1.11.29 Configuration import.php configuration_file/course_path/home_path deserialization (EUVD-2025-208171)
A vulnerability was found in Chamilo LMS up to 1.11.29. It has been declared as critical. This issue affects some unknown processing of the file /plugin/vchamilo/views/import.php of the component Configuration Handler. The manipulation of the argument configuration_file/course_path/home_path results in deserialization.
This vulnerability is identified as CVE-2025-50198. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.