Cross-site scripting in Chamilo LMS - CVE-2025-55208

 

Cross-site scripting in Chamilo LMS - CVE-2025-55208

Published: April 24, 2026


Vulnerability identifier: #VU127545
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2025-55208
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in a victim's browser and compromise the victim's account.

The vulnerability exists due to cross-site scripting in the social networks uploaded files feature when processing uploaded file content that is later viewed in the platform. A remote user can upload a specially crafted file to execute arbitrary script in a victim's browser and compromise the victim's account.

User interaction is required when an authenticated user views the malicious content, including through internal messaging features.


Affected software

Chamilo LMS

How to mitigate CVE-2025-55208

Install security update from vendor's website.

Chamilo LMS - update to 1.11.34

External References

Related Security Bulletins