TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2025-52564

MEDIUM
6.1

Beschreibung

Chamilo is a learning management system. Prior to version 1.11.30, the open parameter of help.php fails to properly sanitize user input. This allows an attacker to inject arbitrary HTML, such as underlined text, via a crafted URL. This issue has been patched in version 1.11.30.

CVE Details

CVSS v3.1 Bewertung6.1
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht3/2/2026
Zuletzt geandert3/3/2026
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

chamilo:chamilo_lms

Schwachen (CWE)

CWE-80

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.