Cross-site scripting in Chamilo LMS - CVE-2025-55208
Published: April 24, 2026
Chamilo LMS
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser and compromise the victim's account.
The vulnerability exists due to cross-site scripting in the social networks uploaded files feature when processing uploaded file content that is later viewed in the platform. A remote user can upload a specially crafted file to execute arbitrary script in a victim's browser and compromise the victim's account.
User interaction is required when an authenticated user views the malicious content, including through internal messaging features.