Cross-site scripting in Chamilo LMS - CVE-2025-59543

 

Cross-site scripting in Chamilo LMS - CVE-2025-59543

Published: April 24, 2026


Vulnerability identifier: #VU127543
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2025-59543
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to take over accounts.

The vulnerability exists due to cross-site scripting in the course description field when rendering course information pages. A remote user can inject malicious JavaScript into the course description field to take over accounts.

User interaction is required to view the course information page.


Affected software

Chamilo LMS

How to mitigate CVE-2025-59543

Install security update from vendor's website.

Chamilo LMS - update to 1.11.34

External References

Related Security Bulletins