Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nospaceavailable

#46908of 53,624
5.4Total CVSS
Vulnerabilities · 1
PT-2025-16887
5.4
2025-04-16
Unknown · Chamilo Lms · CVE-2025-26153
**Name of the Vulnerable Software and Affected Versions** Chamilo LMS version 1.11.28 **Description** A Stored XSS issue exists in the message compose feature. Attackers can inject malicious scripts into messages, which execute when victims, such as administrators, reply to the message. **Recommendations** For version 1.11.28, consider disabling the message compose feature until a patch is available to prevent exploitation. Restrict access to the message reply functionality to minimize the risk of malicious script execution. Avoid using the vulnerable message compose feature until the issue is resolved.