PT-2026-22588 · Chamilo · Chamilo
Published
2026-03-02
·
Updated
2026-03-02
·
CVE-2025-50186
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Chamilo versions prior to 1.11.30
Description
Chamilo, a learning management system, contains a stored cross-site scripting (XSS) issue. This is due to inadequate sanitization of CSV filenames. An attacker can upload a CSV file with a malicious name, such as
<img src=q onerror=prompt(8)>.csv, which results in JavaScript execution when administrators or users with access to import logs or file views access it. The vulnerability is triggered when a maliciously crafted CSV filename is processed, allowing for the injection of arbitrary JavaScript code. The vulnerable component is the CSV file processing functionality.Recommendations
Update to Chamilo version 1.11.30 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chamilo