Stored Cross-Site Scripting Vulnerability in Chamilo Learning Management System
CVE-2025-59542

9.1CRITICAL

Key Information:

Vendor

Chamilo

Vendor
CVE Published:
6 March 2026

What is CVE-2025-59542?

A stored cross-site scripting (XSS) vulnerability exists in Chamilo LMS prior to version 1.11.34. This issue allows an attacker with limited privileges, such as a trainer, to inject malicious JavaScript into the course learning path Settings field. When another user, including administrators, views the compromised course information page, the injected script executes in their browser. This can lead to the exfiltration of sensitive session cookies or tokens, potentially resulting in unauthorized account access and complete account takeover for higher-privileged users. The vulnerability has been addressed in the latest release.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

chamilo-lms < 1.11.34

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.