CVE-2025-59542Disclosure(chamilo / chamilo_lms)

LOWCVSS 9.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch chamilo chamilo_lms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the course learning path Settings field, an attacker with a low-privileged account (e.g., trainer) can execute arbitrary JavaScript code in the context of any other user viewing the course information page, including administrators. This allows an attacker to exfiltrate sensitive session cookies or tokens, resulting in account takeover (ATO) of higher-privileged users. This issue has been patched in version 1.11.34.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chamilo_lms

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-06); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
chamilo_lms

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-06: 4Mentions · 2026-03-11: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-06: 4Technical Details · 2026-03-11: 103-0603-11
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-064
Disclosure3Patch1
2026-03-111
Disclosure1
Full discourse5 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-59542 (CVSS:9.0, CRITICAL) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerab..https://nvd.nist.gov/vuln/detail/CVE-2025-59542 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The text announces a critical stored XSS vulnerability (CVE‑2025‑59542) in Chamilo prior to version 1.11.34, providing the CVSS score and a reference to the NVD entry.

    0000054
    172 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-59542 Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into … https://www.cve.org/CVERecord?id=CVE-2025-59542

    Post summary

    The statement announces a stored XSS vulnerability in Chamilo before version 1.11.34, enabling malicious JavaScript insertion, but does not provide PoC, exploit code, or patch information.

    00000183
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-59542 - Critical Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the course learning p... https://www.thehackerwire.com/vulnerability/CVE-2025-59542/ https://t.co/TsSkPd6jTZ

    Post summary

    The text announces the discovery of a critical stored XSS vulnerability in Chamilo (CVE‑2025‑59542), but does not supply a PoC, exploit code, evidence of active exploitation, or any patch information.

    0000072
    125 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-59542 - Chamilo: Account Takeover via Stored XSS in Course Learning Paths Intel Report: https://ift.tt/1RyGCn3

    Post summary

    The alert announces CVE‑2025‑59542 as a Stored XSS vulnerability in Chamilo that can lead to account takeover, but no PoC, exploit, or mitigation is disclosed.

    0000083
    343 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2025-59542: CRITICAL] Chamilo LMS <1.11.34 had a stored XSS flaw. Attackers can run malicious JavaScript via course settings, leading to account takeover. Upgrade to 1.11.34 to fix this issue.#cve,CVE-2025-59542,#cybersecurity https://cvefind.com/CVE-2025-59542

    Post summary

    This post alerts to a critical stored XSS vulnerability in Chamilo LMS versions prior to 1.11.34, potentially enabling account takeover via JavaScript in course settings, and recommends upgrading to version 1.11.34 to remediate the issue.

    0000081
    597 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchamilochamilo_lms---

Explore more