Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
4.8
Chamilo learning management system: Malicious scripts can be injected.
CVE-2025-52470
Summary
Chamilo's learning management system has a security flaw that allows attackers to inject malicious code. This can happen when an administrator adds a new category, and the code can then be executed later, potentially allowing the attacker to access sensitive areas of the system. Update to version 1.11.30 to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| chamilo | chamilo_lms | <= 1.11.30 | – |
Original title
Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exists in the session_category_add.php script. The vulnerability is caused by im...
Original description
Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exists in the session_category_add.php script. The vulnerability is caused by improper sanitization of the Category Name field, allowing privileged users to inject persistent JavaScript payloads. The injected script is later executed when accessing add_many_sessions_to_category.php, potentially compromising administrative sessions. This issue has been patched in version 1.11.30.
nvd CVSS3.1
4.8
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
Published: 2 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026