CVE-2025-59543

CRITICAL

Chamilo LMS < 1.11.34 - Authenticated Stored Cross-Site Scripting via Course Description Field

Title source: llm
STIX 2.1

Description

Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the course description field, an attacker with a low-privileged account (e.g., trainer) can execute arbitrary JavaScript code in the context of any other user viewing the course information page, including administrators. This allows an attacker to exfiltrate sensitive session cookies or tokens, resulting in account takeover (ATO) of higher-privileged users. This issue has been patched in version 1.11.34.

References (2)

Core 2

Scores

CVSS v3 9.0
EPSS 0.0025
EPSS Percentile 16.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (1)
chamilo/chamilo_lms < 1.11.34
Published Mar 06, 2026
Tracked Since Mar 06, 2026