Arbitrary file upload in Chamilo LMS - CVE-2026-45140
Published: July 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to unrestricted upload of file with dangerous type in public/plugin/CStudio/editor/import-project/inc/big-upload.php in the CStudio plugin when handling file uploads. A remote attacker can upload a malicious php file and access it to execute arbitrary code.