top of page
perceptive_background_267k.jpg

Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teach…

Published:

1 maart 2026 om 23:00:00

Alert date:

2 maart 2026 om 16:01:55

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

A stored cross-site scripting (XSS) vulnerability has been discovered in Chamilo learning management system prior to version 1.11.30. The vulnerability exists in the glossary function and allows users with Teacher role privileges to inject malicious JavaScript code that can target administrators. This represents a privilege escalation attack vector where lower-privileged users can potentially compromise administrator accounts. The vulnerability has been addressed in Chamilo version 1.11.30 with multiple commits providing the necessary patches.

Technical details

Mitigation steps:

Affected products:

Chamilo LMS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page