Cross-Site Scripting Vulnerability in Chamilo LMS by Chamilo Foundation
CVE-2026-45143

9CRITICAL

Key Information:

Vendor

Chamilo

Vendor
CVE Published:
17 September 2026

What is CVE-2026-45143?

Chamilo LMS, an open-source learning management system, is susceptible to a cross-site scripting (XSS) vulnerability where private message content is stored without proper server-side sanitization. Authenticated low-privilege users, such as students, can manipulate the message creation flow to address crafted content to administrators. When the recipient views their inbox or messages, the malicious content executes in their browser immediately, posing risks of session credential exposure and unauthorized actions executed as an administrator. The vulnerability has been addressed in version 2.0.1.

Affected Version(s)

chamilo-lms >= 2.0.0, < 2.0.1

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.