9
CVE-2026-45143
- EPSS -
- Veröffentlicht 17.09.2026 20:09:57
- Zuletzt bearbeitet 29.09.2026 19:07:47
- Erkennungen
Chamilo LMS: Student-to-admin stored XSS in private messages via v-html
Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private Message.content without server-side sanitization and renders it as HTML in assets/vue/views/message/MessageShow.vue and public/main/template/default/message/view_message.html.twig. An authenticated low-privilege user, including a student, can directly address crafted message content to an administrator because the message creation flow permits a sender to select another user as the recipient. The content executes in the recipient's browser when the recipient opens the routine inbox or message view, without requiring a link click, and can expose session credentials or permit actions as the administrator. This vulnerability is fixed in 2.0.1.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerchamilo
≫
Produkt
chamilo-lms
Version
>= 2.0.0, < 2.0.1
Status
affected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 9 | 2.3 | 6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://github.com/chamilo/chamilo-lms/releases/tag/v2.0.1
https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-x88v-rg6r-vqq6
https://github.com/chamilo/chamilo-lms/commit/b2c91c021fc5ab7e91feb4927c4c676f77034ac5