PT-2025-39214 · Chamilo · Chamilo

Published

2025-09-23

·

Updated

2026-03-11

·

CVE-2025-59543

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chamilo versions prior to 1.11.34
Description Chamilo is a learning management system susceptible to a stored cross-site scripting (XSS) issue. An attacker with limited access, such as a trainer, can inject malicious JavaScript into the course description field. This allows the execution of arbitrary JavaScript code when other users, including administrators, view the course information page. Successful exploitation can lead to the theft of sensitive session cookies or tokens, potentially resulting in account takeover (ATO) of higher-privileged users. The vulnerable parameter is the course description field.
Recommendations Update to version 1.11.34 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-59543
GHSA-P32Q-6GH3-3GCV

Affected Products

Chamilo