PT-2026-22615 · Chamilo · Chamilo

Published

2026-03-02

·

Updated

2026-03-07

·

CVE-2025-52468

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chamilo versions prior to 1.11.30
Description Chamilo, a learning management system, contains an input validation issue when importing user data from CSV files. Insufficient sanitization of the "Last Name", "First Name", and "Username" fields allows for the injection of a stored cross-site scripting (XSS) payload. This payload is triggered when a user profile is viewed, potentially leading to malicious script execution within the context of an authenticated user. The vulnerable code does not properly validate user-supplied data during the import process.
Recommendations Update to version 1.11.30 or later to address this vulnerability.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-52468
GHSA-HC3C-8P55-XH4R

Affected Products

Chamilo