CVE-2025-50191 | Chamilo LMS up to 1.11.29 hotpotatoes.php sql injection (GHSA-82qx-25j7-5639 / EUVD-2025-208160)
A vulnerability, which was classified as critical, has been found in Chamilo LMS up to 1.11.29. Affected by this issue is some unknown functionality of the file /main/exercise/hotpotatoes.php. This manipulation causes sql injection.
The identification of this vulnerability is CVE-2025-50191. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.