PT-2026-23632 · Chamilo · Chamilo

Published

2026-03-06

·

Updated

2026-03-06

·

CVE-2025-59540

CVSS v4.0

6.4

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Chamilo versions prior to 1.11.34
Description Chamilo is a learning management system. A stored cross-site scripting (XSS) issue exists that allows a staff account to execute arbitrary JavaScript in the browser of admin users with higher privileges. The issue occurs because feedback input on the exercise history page is not properly encoded before rendering, enabling malicious scripts to persist in the database and execute when viewed. The vulnerable component is the rendering of feedback input.
Recommendations Update to version 1.11.34 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-59540
GHSA-59H4-34MX-M67M

Affected Products

Chamilo