Cross-site scripting in Chamilo LMS - CVE-2026-32893
Published: April 24, 2026
Chamilo LMS
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in a victim's browser.
The vulnerability exists due to cross-site scripting in public/main/exercise/question_list_admin.inc.php when generating pagination links from user-supplied GET parameters. A remote user can send a specially crafted request to execute arbitrary JavaScript in a victim's browser.
User interaction is required, and exploitation occurs in an authenticated teacher's browser.