CVE-2025-50188 | Chamilo LMS up to 1.11.29 Database Query syncparams.php Value sql injection (GHSA-96j3-x45m-9q3r / EUVD-2025-208157)
A vulnerability classified as critical has been found in Chamilo LMS up to 1.11.29. Affected is an unknown function of the file /plugin/vchamilo/views/syncparams.php of the component Database Query Handler. The manipulation of the argument Value leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-50188. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.