Cross-Site Scripting Vulnerability in Chamilo LMS by Chamilo Foundation
CVE-2026-45143
9CRITICAL
What is CVE-2026-45143?
Chamilo LMS, an open-source learning management system, is susceptible to a cross-site scripting (XSS) vulnerability where private message content is stored without proper server-side sanitization. Authenticated low-privilege users, such as students, can manipulate the message creation flow to address crafted content to administrators. When the recipient views their inbox or messages, the malicious content executes in their browser immediately, posing risks of session credential exposure and unauthorized actions executed as an administrator. The vulnerability has been addressed in version 2.0.1.
Affected Version(s)
chamilo-lms >= 2.0.0, < 2.0.1
