CVE-2025-50189 | Chamilo LMS up to 1.11.29 Database Query copy_course_session_selected.php Login sql injection (GHSA-vxx3-648j-7p4r / EUVD-2025-208158)
A vulnerability described as critical has been identified in Chamilo LMS up to 1.11.29. This impacts an unknown function of the file /main/coursecopy/copy_course_session_selected.php of the component Database Query Handler. Executing a manipulation of the argument Login can lead to sql injection.
This vulnerability is handled as CVE-2025-50189. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.