Cross-site request forgery in Chamilo LMS - CVE-2025-59541
Published: April 24, 2026
Chamilo LMS
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service and modify data.
The vulnerability exists due to cross-site request forgery in the project module when handling project deletion requests. A remote attacker can trick the victim into visiting a malicious page to cause a denial of service and modify data.
User interaction is required, and the action is performed using the victim's existing session cookies.