Chamilo: HTML injection via open parameter
Vulnerability Description
Chamilo is a learning management system. Prior to version 1.11.30, the open parameter of help.php fails to properly sanitize user input. This allows an attacker to inject arbitrary HTML, such as underlined text, via a crafted URL. This issue has been patched in version 1.11.30.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-52564
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-6fmm-qrx4-wgqc
- https://github.com/chamilo/chamilo-lms/commit/083b1d2b0c29b0cc0313a28165ad47bebae9dcb2
- https://github.com/chamilo/chamilo-lms/commit/1ee2d8bb61b67e08946cd80b1a9b92c1a9959c7b
- https://github.com/chamilo/chamilo-lms/releases/tag/v1.11.30
More from chamilo
View All →Affected Vendor
chamilo
View all reports →