Chamilo LMS has Stored Cross Site Scripting on Social Networks Uploaded Files
Vulnerability Description
Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `Social Networks`. Through it, a low-privilege user can execute arbitrary code in the admin user inbox, allowing takeover of the admin account. Version 1.11.34 fixes the issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-55208
Credits & Attribution
No credits recorded in the NVD database.
More from chamilo
View All →Affected Vendor
chamilo
View all reports →