CVE-2025-59541: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-59541 is a Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS that allows an attacker to delete course projects without the victim's consent. It affects Chamilo LMS versions prior to 1.11.34 (specifically confirmed in v1.11.32). The vulnerability was published on March 6, 2026, and patched in version 1.11.34 released February 28, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-352 (Cross-Site Request Forgery) and stems from the absence of anti-CSRF token validation on the project deletion endpoint within Chamilo's course module. The deletion action is triggered via a GET-based HTTP request, meaning the application relies solely on the victim's session cookies to authorize the operation without verifying the request's origin. An attacker can craft a malicious web page containing a hidden request (e.g., an <img> tag or auto-submitting form) that, when visited by an authenticated Trainer, silently triggers the project deletion on their behalf. No special privileges are required on the attacker's side; only the victim must be authenticated (GitHub Advisory).

Impact

Successful exploitation results in unauthorized and irreversible deletion of course projects, causing data loss and disruption of educational activities. Both Trainer and Administrator roles are affected, as both can create and manage projects. There is no direct confidentiality impact (no data exfiltration), but integrity and availability are rated High due to the permanent loss of course content and the potential for widespread disruption in collaborative educational environments (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.015% (0.000150), indicating a very low probability of exploitation in the near term. The attack requires user interaction — specifically, an authenticated Trainer must visit a malicious page — but requires no attacker privileges and has low attack complexity. The vulnerability has not been added to the CISA KEV catalog (GitHub Advisory, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify Chamilo LMS instances running versions prior to 1.11.34 (e.g., v1.11.32) that are accessible over the network. Confirm the target has authenticated Trainer or Administrator users.
  2. Identify the vulnerable endpoint: Determine the GET-based project deletion URL within the Chamilo course module (e.g., a URL of the form /main/work/work.php?action=delete_work&id=<project_id>&cidReq=<course_code>).
  3. Craft a malicious page: Create an HTML page containing a resource that automatically triggers the deletion request using the victim's session, such as <img src="https://target-chamilo.example.com/main/work/work.php?action=delete_work&id=<project_id>&cidReq=<course_code>" />.
  4. Deliver the payload: Trick an authenticated Trainer into visiting the malicious page via phishing email, forum post, or other social engineering vector.
  5. Project deletion triggered: Upon page load, the victim's browser sends the GET request with their session cookie, causing the Chamilo server to delete the targeted project without any CSRF token validation (GitHub Advisory).

Indicators of compromise

  • Logs: Chamilo web server access logs showing GET requests to the project deletion endpoint (e.g., /main/work/work.php?action=delete_work) originating from unexpected or external referrer URLs, or with a Referer header pointing to an unknown external domain.
  • Application Activity: Sudden or unexplained deletion of course projects, particularly outside of normal working hours or without corresponding user-initiated activity in audit logs.
  • Network: HTTP GET requests to project deletion endpoints arriving with referrer headers from external or suspicious domains, rather than from within the Chamilo application itself.

Mitigation and workarounds

The primary remediation is to upgrade Chamilo LMS to version 1.11.34 or later, which addresses the missing CSRF protections (Chamilo Release). As interim mitigations, administrators should implement the SameSite=Strict or SameSite=Lax attribute on session cookies to reduce CSRF risk, and deploy Content Security Policy (CSP) headers. Users should be advised to avoid clicking suspicious links while authenticated to Chamilo. Consider adding re-authentication requirements for sensitive destructive operations such as project deletion (GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher prakhar0x01 and disclosed via GitHub Security Advisories on March 5, 2026. Brief mentions appeared on Mastodon via @thehackerwire and were tracked by several vulnerability aggregators including VulnDB and cvefeed.io. No significant broader media coverage or notable researcher commentary beyond the initial advisory has been identified (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management