Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-105806. PoCs published by Vulnerability-Lab.
AI-analyzed exploit summary This is a proof-of-concept for a persistent XSS vulnerability in Chamilo LMS, where the 'title' parameter in the 'work/upload.php' file is vulnerable to script injection. The payload is executed when viewed in 'view.php'.
Description
Chamilo LMS - Persistent Cross-Site Scripting
Exploits (1)
exploitdb
WORKING POC
by Vulnerability-Lab · textwebappsphp
https://www.exploit-db.com/exploits/39474
This is a proof-of-concept for a persistent XSS vulnerability in Chamilo LMS, where the 'title' parameter in the 'work/upload.php' file is vulnerable to script injection. The payload is executed when viewed in 'view.php'.
Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:
Chamilo LMS (version not specified)
Auth required
Prerequisites:
Low-privileged user account · Access to the 'Assignments' feature
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026