Cross-site scripting in Chamilo LMS - CVE-2026-61577
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in a victim's authenticated session.
The vulnerability exists due to cross-site scripting in the social wall content rendering path when rendering stored wall posts or comments containing crafted HTML. A remote user can submit a crafted wall post or comment to execute arbitrary JavaScript in a victim's authenticated session.
User interaction is required when a victim opens the affected user's social wall.