CVE-2026-35196
chamilo chamilo-lms, chamilo lms
Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an OS Command Injection vulnerability exists in the main/inc/ajax/gradebook.ajax.php endpoint within the export_all_certificates action, where the course code retrieved from the session variable $_SESSION['_cid'] via api_get_course_id() is concatenated directly into a shell_exec() command string without sanitization or escaping using escapeshellarg(). If an attacker can manipulate or poison their session data to inject shell metacharacters into the _cid variable, they can achieve arbitrary command exe...
- CVSS
- 8.8
- EPSS
- 1.76% 75.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.15