CVE-2025-52469Disclosure(chamilo / chamilo_lms)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Chamilo is a learning management system. Prior to version 1.11.30, a logic vulnerability in the friend request workflow of Chamilo’s social network module allows an authenticated user to forcibly add any user as a friend by directly calling the AJAX endpoint. The attacker can bypass the normal flow of sending and accepting friend requests, and even add non-existent users. This breaks access control and social interaction logic, with potential privacy implications. This issue has been patched in version 1.11.30.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-841

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chamilo_lms

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-05); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
chamilo_lms

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 103-0503-0603-07
Signal classification1 categories
Disclosure
3100.0%
Referenced assets1 URL
By indicator
Full discourse3 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-52469 (CVSS:7.1, HIGH) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, a logic vulnerability in the friend request workflow ..https://nvd.nist.gov/vuln/detail/CVE-2025-52469 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The text announces a high‑severity logic vulnerability (CVSS 7.1) affecting Chamilo’s friend request workflow before version 1.11.30, with no PoC, exploit, or patch information provided.

    00000123
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-52469 (CVSS:7.1, HIGH) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, a logic vulnerability in the friend request workflow ..https://nvd.nist.gov/vuln/detail/CVE-2025-52469 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2025-52469, a logic flaw in Chamilo’s friend request workflow rated CVSS 7.1, but provides no PoC, exploit, or mitigation details.

    0000049
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-52469 (CVSS:7.1, HIGH) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, a logic vulnerability in the friend request workflow ..https://nvd.nist.gov/vuln/detail/CVE-2025-52469 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE-2025-52469, provides its CVSS score and a brief description of a logic flaw, but does not mention exploits, patches, or active attacks.

    0000036
    173 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchamilochamilo_lms---

Explore more