CRITICAL🇵🇱 Wersja polska

CVE-2025-59543

CVSS 9.0v3.1pub. 2026-03-06upd. 2026-03-09

Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the course description field, an attacker with a low-privileged account (e.g., trainer) can execute arbitrary JavaScript code in the context of any other user viewing the course information page, including administrators. This allows an attacker to exfiltrate sensitive session cookies or tokens, resulting in account takeover (ATO) of higher-privileged users. This issue has been patched in version 1.11.34.

🤖 AI Analysis
How it works

An attacker with a low-privilege account (e.g., instructor) can inject malicious JavaScript code into the course description field. This code is permanently stored in the system (stored XSS) and automatically executed in the browser of every user who views the page with course information. In this way, the attacker can intercept the victim's session cookies or authentication tokens and use them to take over their account.

Impact

An attacker can steal session cookies or authentication tokens of any user viewing the infected course, including administrators, leading to complete account takeover.

Mitigation & patch

Chamilo LMS should be updated to version 1.11.34, in which the vulnerability has been patched. The patch is available in the official GitHub repository of the vendor.

Who is affected

Chamilo LMS in all versions before 1.11.34

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
  • Chamilo Lms

    APP
    Chamilo
    < 1.11.34
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2026-33698CRITICAL9.3PL ✓same product

Chamilo LMS: ominięcie uwierzytelnienia i modyfikacja plików przez katalog install

CVE-2026-32892CRITICAL9.1PL ✓same product

OS Command Injection w Chamilo LMS — funkcja przenoszenia plików

CVE-2026-33707CRITICAL9.4PL ✓same product

Chamilo LMS — przewidywalny token resetowania hasła (CWE-640)

CVE-2026-28430CRITICAL9.3PL ✓same product

Niezauwytoryzowany SQL injection w Chamilo LMS — przejęcie konta administratora

CVE-2025-59542CRITICAL9.0PL ✓same product

Stored XSS w Chamilo LMS — przejęcie kont wyżej uprzywilejowanych użytkowników