CVE-2025-26153: XSS
A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious scripts into messages, which execute when victims, such as administrators, reply to the message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26153?
CVE-2025-26153 is classified as a high-severity Stored XSS vulnerability affecting Chamilo LMS.
How do I fix CVE-2025-26153?
To fix CVE-2025-26153, update Chamilo LMS to version 1.11.29 or later, which addresses the vulnerability.
Who is affected by CVE-2025-26153?
Administrators and other users who interact with the message compose feature in Chamilo LMS 1.11.28 are affected by CVE-2025-26153.
What type of attacks can be executed using CVE-2025-26153?
CVE-2025-26153 allows attackers to inject malicious scripts that execute when victims reply to messages within Chamilo LMS.
Is CVE-2025-26153 a remote or local vulnerability?
CVE-2025-26153 is a remote vulnerability that can be exploited by attackers without physical access to the affected system.