PT-2026-22588 · Chamilo · Chamilo

Published

2026-03-02

·

Updated

2026-03-02

·

CVE-2025-50186

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Chamilo versions prior to 1.11.30
Description Chamilo, a learning management system, contains a stored cross-site scripting (XSS) issue. This is due to inadequate sanitization of CSV filenames. An attacker can upload a CSV file with a malicious name, such as <img src=q onerror=prompt(8)>.csv, which results in JavaScript execution when administrators or users with access to import logs or file views access it. The vulnerability is triggered when a maliciously crafted CSV filename is processed, allowing for the injection of arbitrary JavaScript code. The vulnerable component is the CSV file processing functionality.
Recommendations Update to Chamilo version 1.11.30 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-50186
GHSA-WRX6-5V5R-MMGX

Affected Products

Chamilo