« Volver al listado

CVE-2026-35196

Estado: AnalizadaAlta (8.8)—

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an OS Command Injection vulnerability exists in the main/inc/ajax/gradebook.ajax.php endpoint within the export_all_certificates action, where the course code retrieved from the session variable $_SESSION['_cid'] via api_get_course_id() is concatenated directly into a shell_exec() command string without sanitization or escaping using escapeshellarg().

Leer descripción completaMostrar menos

If an attacker can manipulate or poison their session data to inject shell metacharacters into the _cid variable, they can achieve arbitrary command execution on the underlying server. Successful exploitation grants full access to read system files and credentials, alters the application and database, or disrupts server availability. This issue has been fixed in version 2.0.0-RC.3.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

CWE-78 (OS Command Injection) en endpoint remoto con PR:L confirma T1210. El shell_exec() sin sanitización permite ejecución de comandos (T1059). Acceso a archivos del sistema y credenciales (T1005) y alteración de datos (T1565.001) son impactos explícitos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-35196",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-35196",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-15T14:27:21.595475Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "chamilo",
          "product": "chamilo-lms",
          "versions": [
            {
              "status": "affected",
              "version": "< 2.0.0-RC.3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-04-14T22:16:31.993",
  "references": [
    {
      "url": "https://github.com/chamilo/chamilo-lms/commit/62671e5e268f235cddfba704edee90f35c234df1",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/chamilo/chamilo-lms/releases/tag/v2.0.0-RC.3",
      "tags": [
        "Product",
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-crc6-r6c7-44q3",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an OS Command Injection vulnerability exists in the main/inc/ajax/gradebook.ajax.php endpoint within the export_all_certificates action, where the course code retrieved from the session variable $_SESSION['_cid'] via api_get_course_id() is concatenated directly into a shell_exec() command string without sanitization or escaping using escapeshellarg(). If an attacker can manipulate or poison their session data to inject shell metacharacters into the _cid variable, they can achieve arbitrary command execution on the underlying server. Successful exploitation grants full access to read system files and credentials, alters the application and database, or disrupts server availability. This issue has been fixed in version 2.0.0-RC.3."
    },
    {
      "lang": "es",
      "value": "Chamilo LMS es un sistema de gestión del aprendizaje de código abierto. En versiones anteriores a la 2.0.0-RC.3, existe una vulnerabilidad de inyección de comandos del sistema operativo en el endpoint main/inc/ajax/gradebook.ajax.php dentro de la acción export_all_certificates, donde el código del curso recuperado de la variable de sesión $_SESSION['_cid'] a través de api_get_course_id() se concatena directamente en una cadena de comandos shell_exec() sin saneamiento o escape utilizando escapeshellarg(). Si un atacante puede manipular o envenenar sus datos de sesión para inyectar metacaracteres de shell en la variable _cid, pueden lograr la ejecución arbitraria de comandos en el servidor subyacente. La explotación exitosa otorga acceso completo para leer archivos del sistema y credenciales, altera la aplicación y la base de datos, o interrumpe la disponibilidad del servidor. Este problema ha sido solucionado en la versión 2.0.0-RC.3."
    }
  ],
  "lastModified": "2026-07-24T21:10:00.143",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34085140-9203-4B20-9036-743718F1A4F8",
              "versionEndIncluding": "1.11.38"
            },
            {
              "criteria": "cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4AF7661F-C1F7-4CAB-BBDF-FC5BF7F5BEB8"
            },
            {
              "criteria": "cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE56AF71-9D53-42C6-980D-09E1C418ED87"
            },
            {
              "criteria": "cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01195674-9E1A-4C07-B7D3-0F0CC2E6511B"
            },
            {
              "criteria": "cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BAE63449-5A56-4302-A4BF-F3D19FC96A80"
            },
            {
              "criteria": "cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A84A06F9-5AB7-4703-8153-33AC68882B95"
            },
            {
              "criteria": "cpe:2.3:a:chamilo:chamilo_lms:2.0.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B91302A3-53DE-4ED0-BAAB-FE9DA03F8242"
            },
            {
              "criteria": "cpe:2.3:a:chamilo:chamilo_lms:2.0.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "46008D4A-96F7-4E04-8256-E115AAAE3383"
            },
            {
              "criteria": "cpe:2.3:a:chamilo:chamilo_lms:2.0.0:beta3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E2BCAFF-D44B-4E67-998A-DF855E27606B"
            },
            {
              "criteria": "cpe:2.3:a:chamilo:chamilo_lms:2.0.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2E7D018-E4C2-45F5-8D9A-DAC947173607"
            },
            {
              "criteria": "cpe:2.3:a:chamilo:chamilo_lms:2.0.0:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DAF96697-6B6D-459D-9510-E5CEEDC2859B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}