
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-50186 is a stored cross-site scripting (XSS) vulnerability in Chamilo LMS affecting versions up to and including 1.11.28. The flaw arises from insufficient sanitization of CSV filenames during the user import process, allowing an attacker to upload a maliciously named file (e.g., <img src=q onerror=prompt(8)>.csv) that executes JavaScript when viewed by administrators or other privileged users. It was disclosed on March 2, 2026, and patched in version 1.11.30. The vulnerability carries a CVSS v3.1 base score of 4.8 (Medium) (GitHub Advisory, Red Hat CVE).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), classified as a stored XSS. The vulnerable endpoint is /main/admin/user_import.php, which stores the raw, unsanitized filename of uploaded CSV files; the stored filename is later rendered without encoding in pages such as /main/admin/download_import_users.php. The fix, applied in commit 9fef8f3, introduces api_replace_dangerous_char() and disable_dangerous_file() calls to sanitize the filename before storage. Exploitation requires the attacker to have (or trick someone with) file upload privileges, and a victim with access to import logs or file views must subsequently load the affected page (GitHub Advisory, Patch Commit).
Successful exploitation allows arbitrary JavaScript to execute in the browser context of any authenticated user — particularly administrators — who views the import logs or file management pages. This can lead to full session hijacking, admin account compromise, persistent in-browser attacks, and tampering with platform settings or user data. Because the payload is stored server-side, it persists and can affect multiple victims over time without further attacker interaction (GitHub Advisory).
A proof-of-concept is publicly referenced in the GitHub security advisory, but there is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.03%, reflecting low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high privileges (upload access) and user interaction (an admin viewing the affected page), which limits the attack surface (GitHub Advisory, Red Hat CVE).
<img src=q onerror=alert(document.cookie)>.csv. The file contents can be a valid CSV to avoid suspicion./main/admin/user_import.php and upload the maliciously named CSV file through the user import form./main/admin/download_import_users.php or any page that renders the stored filename./main/admin/user_import.php with a Content-Disposition filename containing HTML tags (e.g., <img, <script, onerror=, onload=); outbound requests from admin browsers to unexpected external hosts following access to import log pages.app/cache/backup/import_users/ with filenames containing HTML or JavaScript characters (e.g., <, >, onerror).user_import.php with URL-encoded HTML entities in the filename field; subsequent access to download_import_users.php by admin accounts shortly after a suspicious upload.The primary remediation is to upgrade Chamilo LMS to version 1.11.30 or later, which sanitizes uploaded CSV filenames using api_replace_dangerous_char() and disable_dangerous_file() before storage (Patch Commit, Release Notes). As interim mitigations, restrict CSV upload access to the minimum necessary trusted users, implement Content Security Policy (CSP) headers to reduce XSS impact, and monitor import logs for filenames containing HTML or JavaScript characters. Reviewing audit logs for suspicious CSV upload activity is also recommended.
The vulnerability was reported by researcher NaklehZeidan21 and remediated by developer AngelFQC, as credited in the official GitHub security advisory. A technical write-up was published by Infinit Security shortly after disclosure, detailing the exploitation path via user_import.php. No major vendor statements beyond the GitHub advisory or significant broader media coverage have been identified (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."