Cross-site scripting in Chamilo LMS - CVE-2025-55289
Published: April 24, 2026
Chamilo LMS
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in a victim's browser and compromise accounts.
The vulnerability exists due to cross-site scripting in the skill management argumentation parameter when processing user-supplied input. A remote user can submit a specially crafted argumentation value to execute arbitrary JavaScript in a victim's browser and compromise accounts.
The payload executes when viewed by an authenticated user, including administrators, within the LMS context.