Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the course description field, an attacker with a low-privileged account (e.g., trainer) can execute arbitrary JavaScript code in the context of any other user viewing the course information page, including administrators. This allows an attacker to exfiltrate sensitive session cookies or tokens, resulting in account takeover (ATO) of higher-privileged users. This issue has been patched in version 1.11.34.
References
| Link | Resource |
|---|---|
| https://github.com/chamilo/chamilo-lms/releases/tag/v1.11.34 | Product Release Notes |
| https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-p32q-6gh3-3gcv | Vendor Advisory |
Configurations
History
09 Mar 2026, 17:31
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Chamilo chamilo Lms
Chamilo |
|
| CPE | cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:* | |
| References | () https://github.com/chamilo/chamilo-lms/releases/tag/v1.11.34 - Product, Release Notes | |
| References | () https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-p32q-6gh3-3gcv - Vendor Advisory |
09 Mar 2026, 13:36
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
06 Mar 2026, 04:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-06 04:16
Updated : 2026-03-09 17:31
NVD link : CVE-2025-59543
Mitre link : CVE-2025-59543
CVE.ORG link : CVE-2025-59543
JSON object : View
Products Affected
chamilo
- chamilo_lms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
