CRAC Learning - Tech@cracbotDisclosure
The text announces a critical stored XSS vulnerability (CVE‑2025‑59542) in Chamilo prior to version 1.11.34, providing the CVSS score and a reference to the NVD entry.
CVE@CVEnewDisclosure
The statement announces a stored XSS vulnerability in Chamilo before version 1.11.34, enabling malicious JavaScript insertion, but does not provide PoC, exploit code, or patch information.
The Hacker Wire@TheHackerWireDisclosure
The text announces the discovery of a critical stored XSS vulnerability in Chamilo (CVE‑2025‑59542), but does not supply a PoC, exploit code, evidence of active exploitation, or any patch information.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
The alert announces CVE‑2025‑59542 as a Stored XSS vulnerability in Chamilo that can lead to account takeover, but no PoC, exploit, or mitigation is disclosed.
CVEFind.com@CveFindComPatch
This post alerts to a critical stored XSS vulnerability in Chamilo LMS versions prior to 1.11.34, potentially enabling account takeover via JavaScript in course settings, and recommends upgrading to version 1.11.34 to remediate the issue.