CVE-2025-52482: Chamilo: Stored XSS in glossary function via /main/glossary/index.php trigger in /main/tracking/course_log_resources.php
Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teachers role to inject JavaScript malicious code against the administrator. This issue has been patched in version 1.11.30.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52482?
CVE-2025-52482 has been classified as a medium severity vulnerability due to its capability to allow stored XSS attacks.
How do I fix CVE-2025-52482?
To mitigate CVE-2025-52482, upgrade Chamilo to version 1.11.30 or later, which contains the necessary security patches.
Who is affected by CVE-2025-52482?
All users with the Teachers role in Chamilo versions prior to 1.11.30 are affected by CVE-2025-52482.
What type of vulnerability is CVE-2025-52482?
CVE-2025-52482 is identified as a stored cross-site scripting (XSS) vulnerability in the glossary function.
Where does CVE-2025-52482 occur in Chamilo?
CVE-2025-52482 occurs in the glossary function triggered by the /main/glossary/index.php path and related to /main/tracking/course_log_resources.php.