CVE-2025-52482
PoC —CVSS 3.1
8.3 high
EPSS
<1%p31
Published
()
Modified
Description
Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teachers role to inject JavaScript malicious code against the administrator. This issue has been patched in version 1.11.30.
- Vendors
- chamilo
- Products
- chamilo lms
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.