Description
Chamilo LMS before 1.11.42 and 3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious script payloads into survey answers by computing deterministic invitation codes and bypassing authorization checks in the survey submission endpoint. Attackers can submit crafted answers containing unescaped HTML rendered in reporting views to execute arbitrary scripts in the browser sessions of teachers or administrators, enabling persistent backdoor account creation by exploiting the victim's authenticated session.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting allowing arbitrary script execution in teacher and administrator browsers
Action: Apply Patch
AI Analysis

Impact

Chamilo Learning Management System prior to releases 1.11.42 and 3.0.0 contains a stored cross‑site scripting flaw that lets unauthenticated users submit survey answers containing malicious JavaScript. The system fails to validate authorization when storing answers and later renders the raw input in reporting pages viewed by logged‑in teachers or administrators, creating a persistent back‑door that can run arbitrary scripts in the victim’s browser context.

Affected Systems

Users running Chamilo LMS versions before 1.11.42 or before 3.0.0 are vulnerable. The flaw exists in the reporting.php component and the survey submission endpoint of those legacy releases.

Risk and Exploitability

The CVSS score of 5.3 labels the vulnerability as moderate. Its EPSS score of <1% indicates a very low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. Because it can be triggered by unauthenticated requests to the survey submission API, an attacker merely needs to send a crafted survey answer; no additional credentials or exploits are required, making the threat real in environments still using the affected LMS.

Generated by OpenCVE AI on September 21, 2026 at 04:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Chamilo LMS to version 1.11.42 or later 3.0.0 to apply the vendor‑issued security fix.
  • If an immediate upgrade is not possible, alter the survey answer submission endpoint so that only authenticated instructors can post answers and enforce the original authorization checks before saving data.
  • Apply server‑side escaping or sanitization to all stored survey answers before they are rendered in any reporting view, ensuring that injected HTML or JavaScript cannot execute in the browser.
  • As a short‑term measure, consider disabling the survey feature or temporarily hiding the reporting interface until the vulnerability is remediated.

Generated by OpenCVE AI on September 21, 2026 at 04:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:*

Sat, 12 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Chamilo
Chamilo chamilo Lms
Vendors & Products Chamilo
Chamilo chamilo Lms

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Chamilo LMS before 1.11.42 and 3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious script payloads into survey answers by computing deterministic invitation codes and bypassing authorization checks in the survey submission endpoint. Attackers can submit crafted answers containing unescaped HTML rendered in reporting views to execute arbitrary scripts in the browser sessions of teachers or administrators, enabling persistent backdoor account creation by exploiting the victim's authenticated session.
Title Chamilo LMS Stored XSS via Survey Answer Submission in reporting.php
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Chamilo Chamilo Lms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T15:21:45.223Z

Reserved: 2026-08-29T17:20:57.083Z

Link: CVE-2026-82535

cve-icon Vulnrichment

Updated: 2026-09-11T19:21:19.922Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T18:16:59.290

Modified: 2026-09-24T20:43:32.537

Link: CVE-2026-82535

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:45:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')