CVE-2025-59543Disclosure(chamilo / chamilo_lms)

LOWCVSS 9.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch chamilo chamilo_lms systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the course description field, an attacker with a low-privileged account (e.g., trainer) can execute arbitrary JavaScript code in the context of any other user viewing the course information page, including administrators. This allows an attacker to exfiltrate sensitive session cookies or tokens, resulting in account takeover (ATO) of higher-privileged users. This issue has been patched in version 1.11.34.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chamilo_lms

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 4 mentions (2026-03-06); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
chamilo_lms

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-03-06: 4Mentions · 2026-03-09: 1Mentions · 2026-03-11: 1PoC Mentioned / Linked · 2026-03-09: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-06: 4Technical Details · 2026-03-09: 1Technical Details · 2026-03-11: 103-0603-0903-11
Signal classification1 categories
Disclosure
6100.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-064
Disclosure4
2026-03-091
Disclosure1
2026-03-111
Disclosure1
Full discourse6 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-59543 (CVSS:9.0, CRITICAL) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerab..https://nvd.nist.gov/vuln/detail/CVE-2025-59543 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post briefly discloses CVE‑2025‑59543, noting its critical score and that it causes stored XSS in Chamilo before version 1.11.34, without providing exploit or remediation details.

    0000059
    172 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-59543: Chamilo: Account Takeover via St... Low-priv trainer drops XSS in course description, harvests admin cookies when they check the course - classic privilege... https://zerodaysignal.com/vulnerability/CVE-2025-59543 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet reports CVE‑2025‑59543 as an XSS‑based account takeover in Chamilo, sharing a PoC and a link, but provides no evidence of active exploitation, patches, or debunking.

    0000086
    140 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-59543 Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into … https://www.cve.org/CVERecord?id=CVE-2025-59543

    Post summary

    The text announces a stored XSS vulnerability in Chamilo before version 1.11.34, providing concise technical details without mentioning PoC, exploit code, or patches.

    00000163
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-59543 - Critical Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the course descriptio... https://www.thehackerwire.com/vulnerability/CVE-2025-59543/ https://t.co/0KO89YguK0

    Post summary

    The post announces a critical stored XSS flaw in Chamilo (CVE‑2025‑59543) affecting versions prior to 1.11.34, providing basic technical details but no PoC, exploit, or patch.

    0000086
    125 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-59543 - Chamilo: Account Takeover via Stored XSS in Course Description Intel Report: https://ift.tt/xZcUkVO

    Post summary

    The post announces CVE-2025-59543, identifying an account takeover flaw via stored XSS in Chamilo's course description without providing any PoC, exploit, or patch details.

    0000080
    343 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-59543: CRITICAL] Chamilo LMS had a stored XSS vulnerability (pre 1.11.34) allowing attackers to execute JavaScript on other users. Update to the fixed version to avoid security risks.#cve,CVE-2025-59543,#cybersecurity https://cvefind.com/CVE-2025-59543

    Post summary

    The post discloses that Chamilo LMS versions before 1.11.34 contain a stored XSS vulnerability enabling JavaScript execution on other users, and recommends applying the fixed version to mitigate the risk.

    0000086
    597 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchamilochamilo_lms---

Explore more