CVE-2025-52482
8.3
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L
Exploitability: 1.7 / Impact: 6.0
Source: security-advisories@github.com (Secondary)
Description
Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teachers role to inject JavaScript malicious code against the administrator. This issue has been patched in version 1.11.30.
Affected (1)
Products: Chamilo: Chamilo Lms
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.11.30 |
References (5)
Source: security-advisories@github.com
Patch
Source: security-advisories@github.com
Patch
Source: security-advisories@github.com
Patch
Source: security-advisories@github.com
ProductRelease Notes
Source: security-advisories@github.com
ExploitMitigationVendor Advisory
Timeline
No history available yet.