CRITICAL🇵🇱 Wersja polska

CVE-2025-59542

CVSS 9.0v3.1pub. 2026-03-06upd. 2026-03-09

Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the course learning path Settings field, an attacker with a low-privileged account (e.g., trainer) can execute arbitrary JavaScript code in the context of any other user viewing the course information page, including administrators. This allows an attacker to exfiltrate sensitive session cookies or tokens, resulting in account takeover (ATO) of higher-privileged users. This issue has been patched in version 1.11.34.

🤖 AI Analysis
How it works

An attacker injects malicious JavaScript code into the learning path settings field in a course. The injected code is permanently stored in the system and is automatically executed in the browser of every user who views the course information page. The malicious script can steal the victim's session cookies or authentication tokens, which can then be used by the attacker to impersonate a user with higher privileges (account takeover — ATO).

Impact

An attacker can take over accounts of users with higher privileges, including administrators, by stealing their session tokens or cookies. As a result, the attacker gains full control over the compromised accounts and potentially over the entire LMS platform.

Mitigation & patch

Update Chamilo LMS to version 1.11.34 or later, in which the vulnerability has been fixed. The patch is available in the official Chamilo GitHub repository.

Who is affected

Chamilo LMS in all versions before 1.11.34

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
  • Chamilo Lms

    APP
    Chamilo
    < 1.11.34
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2026-33698CRITICAL9.3PL ✓same product

Chamilo LMS: ominięcie uwierzytelnienia i modyfikacja plików przez katalog install

CVE-2026-32892CRITICAL9.1PL ✓same product

OS Command Injection w Chamilo LMS — funkcja przenoszenia plików

CVE-2026-33707CRITICAL9.4PL ✓same product

Chamilo LMS — przewidywalny token resetowania hasła (CWE-640)

CVE-2026-28430CRITICAL9.3PL ✓same product

Niezauwytoryzowany SQL injection w Chamilo LMS — przejęcie konta administratora

CVE-2025-59543CRITICAL9.0PL ✓same product

Stored XSS w Chamilo LMS umożliwiający przejęcie kont administratorów