CVE-2025-52468

Source
https://cve.org/CVERecord?id=CVE-2025-52468
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-52468.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-52468
Aliases
  • GHSA-hc3c-8p55-xh4r
Published
2026-03-02T15:47:46.748Z
Modified
2026-03-03T02:34:36.257734Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Chamilo: Stored XSS Vulnerability via CSV User Import
Details

Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importing user data from CSV files. This flaw occurs due to insufficient sanitization of user data, specifically in the "Last Name", "First Name", and "Username" fields. It allows attackers to inject a stored cross-site scripting (XSS) payload that is triggered when the user profile is viewed, potentially leading to malicious script execution in the context of the authenticated use. This issue has been patched in version 1.11.30.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52468.json"
}
References

Affected packages

Git / github.com/chamilo/chamilo-lms

Affected ranges

Type
GIT
Repo
https://github.com/chamilo/chamilo-lms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.11.30"
        }
    ]
}

Affected versions

1.*
1.10.x.pre-doctrine
Other
CHAMILO_1_10_DEV_ICPNA_20130114
CHAMILO_1_8_6_2_BETA_1
CHAMILO_1_8_6_2_STABLE
CHAMILO_1_8_6_2_STABLE_BIS
CHAMILO_1_8_6_2_STABLE_CUATER
CHAMILO_1_8_6_2_STABLE_TRIS
CHAMILO_1_8_7_1_STABLE_1
CHAMILO_1_8_7_1_STABLE_2
CHAMILO_1_8_7_ALPHA_1
CHAMILO_1_8_7_ALPHA_2
CHAMILO_1_8_7_BETA_1
CHAMILO_1_8_7_RC2
CHAMILO_1_8_7_RC_1
CHAMILO_1_8_7_STABLE
CHAMILO_1_8_7_STABLE_BIS
CHAMILO_1_8_8_2_RC_1
CHAMILO_1_8_8_2_STABLE
CHAMILO_1_8_8_2_STABLE_2
CHAMILO_1_8_8_2_STABLE_3
CHAMILO_1_8_8_4_BETA_1
CHAMILO_1_8_8_4_STABLE
CHAMILO_1_8_8_ALPHA
CHAMILO_1_8_8_BETA_1
CHAMILO_1_8_8_BETA_2
CHAMILO_1_8_8_BETA_3
CHAMILO_1_8_8_STABLE_1
CHAMILO_1_9_0_ALPHA_1
CHAMILO_1_9_0_ALPHA_2
CHAMILO_1_9_0_ALPHA_3
CHAMILO_1_9_0_ALPHA_4
CHAMILO_1_9_0_ALPHA_5
CHAMILO_1_9_0_ALPHA_6
CHAMILO_1_9_0_ALPHA_7
CHAMILO_1_9_0_PRE_ALPHA
CHAMILO_1_9_0_RC_1
CHAMILO_1_9_0_STABLE
CHAMILO_1_9_0_STABLE_2
CHAMILO_1_9_0_STABLE_3
CHAMILO_1_9_2_STABLE
CHAMILO_1_9_2_STABLE_BIS
CHAMILO_1_9_2_STABLE_QUARTER
CHAMILO_1_9_2_STABLE_TRIS
CHAMILO_1_9_4_ALPHA_1
CHAMILO_1_9_4_RC_1
CHAMILO_1_9_4_STABLE
CHAMILO_1_9_6_RC_1
CHAMILO_1_9_6_RC_2
CHAMILO_1_9_6_STABLE
CHAMILO_1_8_8.*
CHAMILO_1_8_8.3_STABLE_4
v1.*
v1.10.6-softaculous
v1.10.6-stable
v1.11.10
v1.11.12
v1.11.12-beta.1
v1.11.14
v1.11.14-beta.1
v1.11.18
v1.11.20
v1.11.20-beta.1
v1.11.22
v1.11.22-beta.1
v1.11.22-beta.2
v1.11.24
v1.11.26
v1.11.26-rc.1
v1.11.28
v1.11.30-rc.1
v1.11.6
v1.11.6-alpha.1
v1.11.8
v1.8.6.1
v1.9.10
v1.9.10.2
v1.9.8
v1.9.8.1
v1.9.8.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-52468.json"