CVE-2025-50199 | Chamilo LMS up to 1.11.29 /index.php openid_url server-side request forgery (EUVD-2025-208172)
A vulnerability was found in Chamilo LMS up to 1.11.29. It has been rated as critical. Impacted is an unknown function of the file /index.php. This manipulation of the argument openid_url causes server-side request forgery.
This vulnerability is tracked as CVE-2025-50199. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.