CVE-2025-55208
Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in Social Networks. Through it, a low-privilege user can execute arbitrary code in the admin user inbox, allowing takeover of the admin account. Version 1.11.34 fixes the issue.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55208.json, https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-2vq2-826h-6hp6, https://nvd.nist.gov/vuln/detail/CVE-2025-55208
