Impact
A stored cross‑site scripting flaw exists in the Chamilo Learning Management System’s user registration form. An attacker who does not need to be logged in can submit a malicious JavaScript payload that is retained in the system’s database. When an administrator later opens the registration record or logs in, the script runs within the admin’s browser context, allowing the attacker to hijack the session and gain full control of the platform.
Affected Systems
All installations of Chamilo LMS running version 1.11.38 or earlier are affected. The vulnerability is limited to the user registration functionality and does not compromise other areas of the system. A patch is already available in version 1.11.40.
Risk and Exploitability
The flaw carries a CVSS score of 9.3, indicating very high severity, while the EPSS score falls below 1 %, implying a low probability of exploitation. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that the registration form is accessible to unauthenticated users; therefore an attacker only needs to submit a registration form. When an administrator later views the registration or logs in, the stored script executes with admin privileges, enabling a full takeover of the LMS.
OpenCVE Enrichment