Impact
Chamilo Learning Management System prior to releases 1.11.42 and 3.0.0 contains a stored cross‑site scripting flaw that lets unauthenticated users submit survey answers containing malicious JavaScript. The system fails to validate authorization when storing answers and later renders the raw input in reporting pages viewed by logged‑in teachers or administrators, creating a persistent back‑door that can run arbitrary scripts in the victim’s browser context.
Affected Systems
Users running Chamilo LMS versions before 1.11.42 or before 3.0.0 are vulnerable. The flaw exists in the reporting.php component and the survey submission endpoint of those legacy releases.
Risk and Exploitability
The CVSS score of 5.3 labels the vulnerability as moderate. Its EPSS score of <1% indicates a very low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. Because it can be triggered by unauthenticated requests to the survey submission API, an attacker merely needs to send a crafted survey answer; no additional credentials or exploits are required, making the threat real in environments still using the affected LMS.
OpenCVE Enrichment