Chamilo Deserialization of Untrusted Data Vulnerability - CVE-2025-52998
Chamilo is a learning management system. Prior to version 1.11.30 in the application deserialization of data is performed the data can be spoofed. An attacker can create objects of arbitrary classes as well as fully control their properties and thus modify the logic of the web application39s operation. This issue has been patched in version 1.11.30.