
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59541 is a Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS that allows an attacker to delete course projects without the victim's consent. It affects Chamilo LMS versions prior to 1.11.34 (specifically confirmed in v1.11.32). The vulnerability was published on March 6, 2026, and patched in version 1.11.34 released February 28, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, Red Hat CVE).
The vulnerability is classified as CWE-352 (Cross-Site Request Forgery) and stems from the absence of anti-CSRF token validation on the project deletion endpoint within Chamilo's course module. The deletion action is triggered via a GET-based HTTP request, meaning the application relies solely on the victim's session cookies to authorize the operation without verifying the request's origin. An attacker can craft a malicious web page containing a hidden request (e.g., an <img> tag or auto-submitting form) that, when visited by an authenticated Trainer, silently triggers the project deletion on their behalf. No special privileges are required on the attacker's side; only the victim must be authenticated (GitHub Advisory).
Successful exploitation results in unauthorized and irreversible deletion of course projects, causing data loss and disruption of educational activities. Both Trainer and Administrator roles are affected, as both can create and manage projects. There is no direct confidentiality impact (no data exfiltration), but integrity and availability are rated High due to the permanent loss of course content and the potential for widespread disruption in collaborative educational environments (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.015% (0.000150), indicating a very low probability of exploitation in the near term. The attack requires user interaction — specifically, an authenticated Trainer must visit a malicious page — but requires no attacker privileges and has low attack complexity. The vulnerability has not been added to the CISA KEV catalog (GitHub Advisory, Red Hat CVE).
/main/work/work.php?action=delete_work&id=<project_id>&cidReq=<course_code>).<img src="https://target-chamilo.example.com/main/work/work.php?action=delete_work&id=<project_id>&cidReq=<course_code>" />./main/work/work.php?action=delete_work) originating from unexpected or external referrer URLs, or with a Referer header pointing to an unknown external domain.The primary remediation is to upgrade Chamilo LMS to version 1.11.34 or later, which addresses the missing CSRF protections (Chamilo Release). As interim mitigations, administrators should implement the SameSite=Strict or SameSite=Lax attribute on session cookies to reduce CSRF risk, and deploy Content Security Policy (CSP) headers. Users should be advised to avoid clicking suspicious links while authenticated to Chamilo. Consider adding re-authentication requirements for sensitive destructive operations such as project deletion (GitHub Advisory).
The vulnerability was reported by security researcher prakhar0x01 and disclosed via GitHub Security Advisories on March 5, 2026. Brief mentions appeared on Mastodon via @thehackerwire and were tracked by several vulnerability aggregators including VulnDB and cvefeed.io. No significant broader media coverage or notable researcher commentary beyond the initial advisory has been identified (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."