PT-2025-39213 · Chamilo · Chamilo

Published

2025-09-23

·

Updated

2026-03-11

·

CVE-2025-59542

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chamilo versions prior to 1.11.34
Description Chamilo is a learning management system susceptible to a stored cross-site scripting (XSS) issue. An attacker with a low-privileged account, such as a trainer, can inject malicious JavaScript into the course learning path Settings field. This allows the execution of arbitrary JavaScript code within the context of any user viewing the course information page, potentially including administrators. Successful exploitation can lead to the exfiltration of sensitive session cookies or tokens, resulting in account takeover (ATO) of higher-privileged users. The vulnerable field is the course learning path Settings field.
Recommendations Upgrade to version 1.11.34 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-59542
GHSA-PXRH-3RCP-H7M6

Affected Products

Chamilo