Looking for the vulnerability index of Invicti's legacy products?
Chamilo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2025-55289 - Vulnerability Database

Chamilo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2025-55289

Critical
Reference: CVE-2025-55289
Title: Chamilo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Chamilo is a learning management system. Prior to version 1.11.34 there is a stored XSS vulnerability in Chamilo LMS (Verison 1.11.32) allows an attacker to inject arbitrary JavaScript into the platforms social network and internal messaging features. When viewed by an authenticated user (including administrators) the payload executes in their browser within the LMS context. This enables full account takeover via session hijacking unauthorized actions with the victims privileges exfiltration of sensitive data and potential self-propagation to other users. This issue has been patched in version 1.11.34.