CVE-2025-55208
Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `S
Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in Social Networks. Through it, a low-privilege user can execute arbitrary code in the admin user inbox, allowing takeover of the admin account.
Version 1.11.34 fixes the issue.
CRITICAL · CVSS 9
EPSS 0.00066
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0