CVE-2025-52482

HIGH

Chamilo <1.11.30 - Stored XSS

Title source: llm
STIX 2.1

Description

Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teachers role to inject JavaScript malicious code against the administrator. This issue has been patched in version 1.11.30.

Scores

CVSS v3 8.3
EPSS 0.0008
EPSS Percentile 23.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (1)
chamilo/chamilo_lms < 1.11.30
Published Mar 02, 2026
Tracked Since Mar 02, 2026