VulnerabilityDeferred
CVE-2025-26153
A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28.
MEDIUM 5.4EPSS 0.34%
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious scripts into messages, which execute when victims, such as administrators, reply to the message.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.34% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Source
- cve@mitre.org
References
- https://gist.github.com/NoSpaceAvailable/234acdf57b5d7b29b2f39090c1686bc8
- https://github.com/chamilo/chamilo-lms/commit/beb07770d674fcc9db6df0e59aab107678c28682
- https://github.com/chamilo/chamilo-lms/commit/d5c29cf39ac30d7364a52bba4036c3e870412066
- https://gist.github.com/NoSpaceAvailable/234acdf57b5d7b29b2f39090c1686bc8
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.