VYPR
Medium severity5.4OSV Advisory· Published Apr 16, 2025· Updated Jun 17, 2026

CVE-2025-26153

CVE-2025-26153

Description

A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious scripts into messages, which execute when victims, such as administrators, reply to the message.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Chamilo/LmsOSV2 versions
    CHAMILO_1_8_7_ALPHA_1, CHAMILO_1_8_7_ALPHA_2, CHAMILO_1_8_7_RC2, …+ 1 more
    • (no CPE)range: CHAMILO_1_8_7_ALPHA_1, CHAMILO_1_8_7_ALPHA_2, CHAMILO_1_8_7_RC2, …
    • (no CPE)range: = 1.11.28

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.