Cross-site scripting in Chamilo LMS - CVE-2026-61655
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in the browser of another administrator and disclose session cookies.
The vulnerability exists due to cross-site scripting in the languages.php admin language management interface when rendering a user-controlled language name inside an HTML value attribute. A remote privileged user can inject a malicious language name containing double quotes to execute arbitrary JavaScript in the browser of another administrator and disclose session cookies.
User interaction is required because another administrator must view or edit the affected language entry.