PT-2026-23510 · Chamilo · Chamilo

Published

2026-03-05

·

Updated

2026-03-17

·

CVE-2025-55208

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chamilo versions prior to 1.11.34
Description Chamilo, a learning management system, contains a Stored Cross-Site Scripting (XSS) issue stemming from insecure file uploads within the Social Networks feature. A user with limited privileges can execute arbitrary code within the administrator's inbox, potentially leading to account takeover. The issue is related to file uploads and the Social Networks component. The vulnerable parameter is not specified.
Recommendations Update to version 1.11.34 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-55208
GHSA-2VQ2-826H-6HP6

Affected Products

Chamilo