CVE-2025-52468Disclosure(chamilo / chamilo_lms)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch chamilo chamilo_lms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importing user data from CSV files. This flaw occurs due to insufficient sanitization of user data, specifically in the "Last Name", "First Name", and "Username" fields. It allows attackers to inject a stored cross-site scripting (XSS) payload that is triggered when the user profile is viewed, potentially leading to malicious script execution in the context of the authenticated use. This issue has been patched in version 1.11.30.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chamilo_lms

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-03-02); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
chamilo_lms

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-03-02: 2Mentions · 2026-03-04: 1Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Patch / Workaround · 2026-03-02: 1Patch / Workaround · 2026-03-04: 1Patch / Workaround · 2026-03-05: 1Technical Details · 2026-03-02: 2Technical Details · 2026-03-04: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 103-0203-0403-0503-0603-07
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-022
Disclosure1Patch1
2026-03-041
Patch1
2026-03-051
Disclosure1
2026-03-061
General1
2026-03-071
Disclosure1
Full discourse6 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-52468 (CVSS:8.8, HIGH) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importi..https://nvd.nist.gov/vuln/detail/CVE-2025-52468 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post documents CVE-2025-52468, a high‑severity input validation flaw in Chamilo before v1.11.30, but does not provide a PoC, exploit, or remediation guidance.

    00000110
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2025-52468 (CVSS:8.8, HIGH) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importi..https://nvd.nist.gov/vuln/detail/CVE-2025-52468 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet merely references CVE‑2025‑52468 with its CVSS score and a brief note of input‑validation weakness, without any PoC, exploit, patch, or active exploitation details.

    0000053
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-52468 (CVSS:8.8, HIGH) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importi..https://nvd.nist.gov/vuln/detail/CVE-2025-52468 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post discloses CVE-2025-52468, an input validation flaw in Chamilo affecting versions before 1.11.30, with a CVSS score of 8.8, and notes that the issue is resolved in newer releases.

    0000040
    173 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `Chamilo` has a stored XSS vulnerability (CVE-2025-52468) via CSV user import. Malicious scripts could execute on profile views. Apply updates. #Chamilo #XSS #infosec https://www.pulsepatch.io/posts/cve-2025-52468-chamilo-stored-xss

    Post summary

    The post reports a stored XSS issue (CVE-2025-52468) in Chamilo that can be triggered via CSV import and urges users to apply updates.

    00000104
    1 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2025-52468: HIGH] Input validation vulnerability in Chamilo LMS prior to v1.11.30 allows XSS attacks via CSV user data import. Update to the latest version to mitigate this security risk.#cve,CVE-2025-52468,#cybersecurity https://cvefind.com/CVE-2025-52468

    Post summary

    The post highlights a high‑severity XSS flaw in Chamilo LMS versions prior to 1.11.30 and recommends updating to the latest release to mitigate the risk.

    0000087
    590 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-52468 - High Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importing user data from CSV files. This flaw occurs due to insufficient sanit... https://www.thehackerwire.com/vulnerability/CVE-2025-52468/ https://t.co/ufZC4qS0O2

    Post summary

    Chamilo LMS has an input validation flaw in CSV import before v1.11.30 (CVE-2025-52468); the post provides technical details but no PoC, exploit, or patch information.

    0000099
    122 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchamilochamilo_lms---

Explore more