CVE-2025-52482
Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teachers role to inject JavaScript malicious code against the administrator. This issue has been patched in version 1.11.30.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/chamilo/chamilo-lms/releases/tag/v1.11.30, https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52482.json, https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-4wcp-3rh3-7wm4, https://nvd.nist.gov/vuln/detail/CVE-2025-52482, https://github.com/chamilo/chamilo-lms/commit/241c569dde0ad0e34d558ae51271f70438189b0e, https://github.com/chamilo/chamilo-lms/commit/82cc07edd8ef316e6b36da7c501120d5c0aeb151, https://github.com/chamilo/chamilo-lms/commit/f9150075246df4ed9755a4a150e25edb468767be
