All verified exploits

CVE-2025-50190 OpenID SQL Injection

Deterministic critical Chamilo Added cve-verified-cve-2025-50190

Detects error-based SQL injection in Chamilo LMS via the OpenID assoc_handle parameter. The openid_verify_assertion() function interpolates user input directly into a SQL query without parameterization.

Is your app exploitable through CVE-2025-50190?

Scan your domain free