CRITICALVulnerability
Verified
Global
NVD CRITICAL: CVE-2026-33698 — Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack ...
·Source: NIST NVD
Updated:
Executive Summary
Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated attacker to modify existing files or create new files where allowed by system permissions. This only affects portals with the main/install/ directory still present and read-accessible. This vulnerability is fixed in 1.11
Analysis
Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated attacker to modify existing files or create new files where allowed by system permissions. This only affects portals with the main/install/ directory still present and read-accessible. This vulnerability is fixed in 1.11.38. CVSS Score: 9.8. Published: 2026-04-10T19:16:23.033.