Chamilo LMS versions prior to 1.11.34 contain an authenticated remote code execution vulnerability in the file upload handling logic. The application relies on MIME-type verification for uploaded content but does not sufficiently validate file extensions and does not enforce safe server-side storage restrictions for uploaded files. As a result, a low-privileged authenticated user can upload a crafted file containing executable code and then trigger its execution to run arbitrary commands on the server. The issue is patched in 1.11.34.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit PoC for CVE-2026-29041 affecting Chamilo LMS 1.11.32. It contains two files: a README describing the vulnerability and exploitation chain, and a single Python exploit script, cvd-10-10.py, which is the main entry point. The script uses the requests library to create an authenticated session, POST credentials to /index.php, then abuse the authenticated AJAX upload endpoint /main/inc/ajax/document.ajax.php?a=ck_uploadimage&cidReq=CVD. It generates a random .php filename and uploads a payload beginning with GIF89a magic bytes followed by PHP code, attempting to bypass MIME-based validation while preserving a dangerous executable extension. After upload, it parses the JSON response for the returned file URL, constructs the full shell URL, and opens an interactive loop that sends commands via the cmd GET parameter to the uploaded web shell. The exploit is operational rather than a simple detector because it includes a working payload and post-exploitation command execution logic. The repository purpose is to demonstrate authenticated remote code execution through unrestricted file upload in Chamilo, specifically relying on MIME-only validation, attacker-controlled filenames, and web-accessible storage of uploaded files.
Repository contains a single Python exploit script (cvd-10-10.py) and a README describing CVE-2026-29041: an authenticated RCE in Chamilo LMS 1.11.32 via unrestricted file upload in the ck_uploadimage AJAX endpoint. The exploit logs in to /index.php with supplied student credentials, crafts a PHP web shell prefixed with GIF89a magic bytes to bypass MIME-only validation, and uploads it to /main/inc/ajax/document.ajax.php?a=ck_uploadimage&cidReq=CVD as multipart form-data under $_FILES['upload']. It sets a ckCsrfToken cookie and also submits ckCsrfToken as a form field. On success, it expects a JSON response containing uploaded=1/true and a relative url to the uploaded file, then enters an interactive loop issuing GET requests to the returned shell URL with ?cmd=<os command> (plus a cache-buster) and prints command output after the marker 'Shell Executed:'. Overall purpose: weaponized PoC for authenticated file-upload-to-RCE by planting an executable PHP file in a web-accessible upload directory.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.