CVE-2025-55208
EUVD-2025-20832605.03.2026, 21:16
Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `Social Networks`. Through it, a low-privilege user can execute arbitrary code in the admin user inbox, allowing takeover of the admin account. Version 1.11.34 fixes the issue.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| chamilo | chamilo_lms | 𝑥 < 1.11.34 |
𝑥
= Vulnerable software versions