Cross-site scripting in Chamilo LMS - CVE-2026-34161
Published: April 24, 2026
Chamilo LMS
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in the victim's browser.
The vulnerability exists due to cross-site scripting in the social post attachment upload functionality when rendering uploaded attachment content via the generated contentUrl. A remote user can upload a malicious HTML file containing JavaScript to execute arbitrary JavaScript in the victim's browser.
User interaction is required when a user accesses the malicious attachment link.