CVE-2025-55208: Chamilo LMS has Stored Cross Site Scripting on Social Networks Uploaded Files
Published Mar 5, 2026
·Updated
Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in Social Networks. Through it, a low-privilege user can execute arbitrary code in the admin user inbox, allowing takeover of the admin account. Version 1.11.34 fixes the issue.
Affected Software
2 affected components
Chamilo Chamilo LMS<1.11.34
Chamilo Chamilo LMS<1.11.34
Event History
Mar 5, 2026
CVE Published
via MITRE·08:58 PM
Data Sourced
via MITRE·08:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55208?
CVE-2025-55208 is classified as a high severity vulnerability due to its ability to allow low-privilege users to execute arbitrary code.
2
How do I fix CVE-2025-55208?
To fix CVE-2025-55208, upgrade to Chamilo LMS version 1.11.34 or later.
3
What type of vulnerability is CVE-2025-55208?
CVE-2025-55208 is a Stored Cross Site Scripting (XSS) vulnerability.
4
Which versions of Chamilo LMS are affected by CVE-2025-55208?
Chamilo LMS versions prior to 1.11.34 are affected by CVE-2025-55208.
5
What can attackers achieve with CVE-2025-55208?
Attackers can execute arbitrary code in the admin user inbox through stored XSS via insecure file uploads.