CVE-2018-25158
Received Received - Intake
Arbitrary File Upload in Chamilo LMS elfinder Enables RCE

Publication date: 2026-02-20

Last updated on: 2026-02-20

Assigner: VulnCheck

Description
Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute PHP files through the elfinder filemanager module. Attackers can upload files with image headers in the social myfiles section, rename them to PHP extensions, and execute arbitrary code by accessing the uploaded files.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-02-20
Last Modified
2026-02-20
Generated
2026-06-16
AI Q&A
2026-02-21
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
chamilo chamilo_lms 1.11.8
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

Chamilo LMS version 1.11.8 has an arbitrary file upload vulnerability in its elfinder filemanager module. Authenticated users can upload files that contain image headers in the social myfiles section. These files can then be renamed to have PHP extensions, allowing the attacker to execute arbitrary PHP code by accessing the uploaded files.

Impact Analysis

This vulnerability allows an authenticated user to upload and execute arbitrary PHP code on the server. This can lead to unauthorized code execution, potentially compromising the server, accessing sensitive data, modifying or deleting information, and disrupting the normal operation of the Chamilo LMS.

Compliance Impact

I don't know

Detection Guidance

I don't know

Mitigation Strategies

I don't know

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2018-25158. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart