Stored Cross-Site Scripting in Chamilo LMS by Chamilo Association
CVE-2026-39878
9.3CRITICAL
What is CVE-2026-39878?
The Chamilo LMS, specifically versions 1.11.38 and prior, is susceptible to a stored cross-site scripting vulnerability within its user registration feature. This flaw permits an unauthenticated attacker to inject and execute arbitrary JavaScript code within an administrator's browser session, potentially leading to full administrative control over the platform. The vulnerability has been addressed and resolved in version 1.11.40, emphasizing the importance of updating to the latest release to safeguard against such threats.
Affected Version(s)
chamilo-lms <= 1.11.38
