Executive brief
Chamilo LMS, a popular learning management system, contains a security flaw in its user registration form. An unauthorized attacker can submit a malicious registration that, when viewed by a system administrator, allows the attacker to take over the administrator's account. This grants the attacker full control over the platform, including access to all student data, grades, and course content.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Chamilo LMS versions <= 1.11.38 due to improper input sanitization in the user registration form (main/auth/inscription.php) and insufficient output encoding in the administrative user list (main/admin/user_list.php). The vulnerability stems from a bypass of the Security::remove_XSS() function using null byte insertion and the failure to use htmlspecialchars() with ENT_QUOTES when rendering user names in HTML 'alt' and 'title' attributes. An unauthenticated attacker can inject malicious JavaScript that executes when an administrator views the user list. This leads to a session takeover and full administrative access to the LMS platform. The issue is resolved in version 1.11.40.
Affected products
- Chamilo Chamilo LMS <= 1.11.38
Timeline
- 2026-07-07: advisory: GitHub Security Advisory published
- 2026-07-20: disclosed: CVE published to NVD
- 2026-07-20: patched: Patch confirmed available in version 1.11.40