CVE-2025-26153

MEDIUM

Chamilo LMS <1.11.28 - XSS

Title source: llm

Description

A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious scripts into messages, which execute when victims, such as administrators, reply to the message.

Exploits (1)

nomisec WORKING POC
by mexeck88 · poc
https://github.com/mexeck88/CSRF-via-stored-XSS-for-PrivEsc

Scores

CVSS v3 5.4
EPSS 0.0014
EPSS Percentile 33.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Published Apr 16, 2025
Tracked Since Feb 18, 2026