Cross-site scripting in Chamilo LMS - CVE-2026-61659
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in victims' browsers.
The vulnerability exists due to cross-site scripting in the group discussion title field when rendering stored thread titles on the group page. A remote user can create a discussion thread with a malicious title to execute arbitrary JavaScript in victims' browsers.
User interaction is required for a group member to visit the group page containing the malicious thread title.