CVE-2018-1999019
9.8
CRITICAL · CVSS 3.1 · EPSS 3.2% (pctl 88)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Chamilo LMS version 11.x contains an Unserialization vulnerability in the "hash" GET parameter for the api endpoint located at /webservices/api/v2.php that can result in Unauthenticated remote code execution. This attack appear to be exploitable via a simple GET request to the api endpoint. This vulnerability appears to have been fixed in After commit 0de84700648f098c1fbf6b807dee28ec640efe62.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.18% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-07-23 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| chamilo | chamilo lms |
References
→ the Explorer · watch your stack · NVD