Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teachers role to inject JavaScript malicious code against the administrator. This issue has been patched in version 1.11.30.
References
Configurations
History
03 Mar 2026, 19:13
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:* | |
| First Time |
Chamilo chamilo Lms
Chamilo |
|
| References | () https://github.com/chamilo/chamilo-lms/commit/241c569dde0ad0e34d558ae51271f70438189b0e - Patch | |
| References | () https://github.com/chamilo/chamilo-lms/commit/82cc07edd8ef316e6b36da7c501120d5c0aeb151 - Patch | |
| References | () https://github.com/chamilo/chamilo-lms/commit/f9150075246df4ed9755a4a150e25edb468767be - Patch | |
| References | () https://github.com/chamilo/chamilo-lms/releases/tag/v1.11.30 - Product, Release Notes | |
| References | () https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-4wcp-3rh3-7wm4 - Exploit, Mitigation, Vendor Advisory |
02 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-02 15:16
Updated : 2026-03-03 19:13
NVD link : CVE-2025-52482
Mitre link : CVE-2025-52482
CVE.ORG link : CVE-2025-52482
JSON object : View
Products Affected
chamilo
- chamilo_lms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
