CVE-2025-52563: Chamilo: Reflected XSS via page parameter
Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability due to insufficient sanitization of the page parameter in the session/adduserstosession.php endpoint. This issue has been patched in version 1.11.30.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52563?
CVE-2025-52563 has been rated as a moderate severity vulnerability due to its potential for exploiting reflected cross-site scripting (XSS).
How do I fix CVE-2025-52563?
To fix CVE-2025-52563, upgrade Chamilo to version 1.11.30 or later, where the XSS vulnerability has been patched.
What type of vulnerability is CVE-2025-52563?
CVE-2025-52563 is a reflected cross-site scripting (XSS) vulnerability that affects the page parameter handling in Chamilo.
Which versions of Chamilo are affected by CVE-2025-52563?
CVE-2025-52563 affects all versions of Chamilo prior to version 1.11.30.
What is the impact of CVE-2025-52563 on users?
The impact of CVE-2025-52563 allows attackers to execute arbitrary scripts in the context of the user's browser, potentially compromising user data.