CVE-2025-50197 | Chamilo LMS up to 1.11.29 sub_language_ajax.inc.php new_language os command injection (EUVD-2025-208166)
A vulnerability, which was classified as critical, was found in Chamilo LMS up to 1.11.29. This affects an unknown function of the file /main/admin/sub_language_ajax.inc.php. The manipulation of the argument new_language results in os command injection.
This vulnerability was named CVE-2025-50197. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.