Cross-site scripting in Chamilo LMS - CVE-2025-59543
Published: April 24, 2026
Chamilo LMS
Detailed vulnerability description
The vulnerability allows a remote user to take over accounts.
The vulnerability exists due to cross-site scripting in the course description field when rendering course information pages. A remote user can inject malicious JavaScript into the course description field to take over accounts.
User interaction is required to view the course information page.