VulnerabilityAnalyzed
CVE-2025-52564
This allows an attacker to inject arbitrary HTML, such as underlined text, via a crafted URL.
MEDIUM 6.9EPSS 0.19%
Does this matter?
Lower severity and a low EPSS score (0.19%). Track it; it rarely justifies an emergency change on its own.
Description
Chamilo is a learning management system. Prior to version 1.11.30, the open parameter of help.php fails to properly sanitize user input. This allows an attacker to inject arbitrary HTML, such as underlined text, via a crafted URL. This issue has been patched in version 1.11.30.
- CVSS 4.0
- 6.9 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.19% probability · 9th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-80
- Affected
- chamilo/chamilo lms
- Source
- security-advisories@github.com
References
- https://github.com/chamilo/chamilo-lms/commit/083b1d2b0c29b0cc0313a28165ad47bebae9dcb2Patch
- https://github.com/chamilo/chamilo-lms/commit/1ee2d8bb61b67e08946cd80b1a9b92c1a9959c7bPatch
- https://github.com/chamilo/chamilo-lms/releases/tag/v1.11.30Product, Release Notes
- https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-6fmm-qrx4-wgqcVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.