Improper Neutralization of Special Elements Used in a Template Engine in Chamilo LMS - CVE-2026-61558
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements used in a template engine in the mail template renderer when compiling a stored mail template from a raw string with the non-sandboxed Twig environment. A remote privileged user can place a crafted Twig payload in the editable mail template to execute arbitrary code.
Execution is triggered when the approval mail is built during new user self-registration if admin approval of accounts is enabled.