CVE-2024-47886

7.2

Chamilo · Chamilo LMS

Chamilo LMS is vulnerable to remote code execution via post-authentication phar deserialization, allowing an administrator to execute arbitrary code on the server through the virtualization plugin.

Executive summary

An authenticated remote code execution vulnerability in Chamilo LMS versions 1.11.12 through 1.11.26 poses a critical risk to server integrity.

Vulnerability

The software is affected by a deserialization of untrusted data (CWE-502) within the vchamilo virtualization plugin, which allows an authenticated administrator to achieve remote code execution.

Business impact

A successful exploit allows an attacker with administrative privileges to execute arbitrary commands on the underlying host operating system. Given the CVSS score of 7.2, this vulnerability facilitates full system compromise, potentially leading to unauthorized data access, lateral movement within the network, and complete loss of control over the learning management system.

Remediation

Immediate Action: Upgrade Chamilo LMS to version 1.11.28 or later to incorporate the vendor-supplied security patch.

Proactive Monitoring: Monitor server logs for unusual processes or unauthorized file system modifications initiated by the web server user.

Compensating Controls: Restrict administrative access to the Chamilo dashboard to trusted IP addresses only, and employ a Web Application Firewall to block suspicious serialized object strings in request parameters.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The risk posed by this vulnerability is significant, as it grants an attacker full code execution capabilities. Organizations using affected versions of Chamilo LMS must prioritize the update to version 1.11.28 immediately to mitigate the threat of server compromise.

More Chamilo CVEs

Sources