CVE-2012-4030: Chamilo Lms

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary files.

Affected products

  • Chamilo Chamilo Lms: before 1.8.8.6 (fixed in 1.8.8.6)

Published 2020-01-10. Last modified 2026-06-16.