ZeroHour

CVE-2025-52482

PoC
CVSS 3.1
8.3 high
EPSS
<1%p31
Published
()
Modified
Description

Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teachers role to inject JavaScript malicious code against the administrator. This issue has been patched in version 1.11.30.

Vendors
chamilo
Products
chamilo lms
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.