Stored Cross-Site Scripting Vulnerability in Chamilo Learning Management System
CVE-2025-59542
What is CVE-2025-59542?
A stored cross-site scripting (XSS) vulnerability exists in Chamilo LMS prior to version 1.11.34. This issue allows an attacker with limited privileges, such as a trainer, to inject malicious JavaScript into the course learning path Settings field. When another user, including administrators, views the compromised course information page, the injected script executes in their browser. This can lead to the exfiltration of sensitive session cookies or tokens, potentially resulting in unauthorized account access and complete account takeover for higher-privileged users. The vulnerability has been addressed in the latest release.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
chamilo-lms < 1.11.34
