Chamilo Improper Neutralization of Directives in Dynamically Evaluated Code (Eval Injection) Vulnerability - CVE-2025-50187
Chamilo is a learning management system. Prior to version 1.11.28 parameter from SOAP request is evaluated without filtering which leads to Remote Code Execution. This issue has been patched in version 1.11.28.