CyberRota Analysis
AI-GeneratedChamilo LMS versions up to 1.11.38 are vulnerable to a stored cross-site scripting flaw in the user registration form, enabling unauthenticated attackers to execute arbitrary JavaScript in an administrator's browser session. This vulnerability can lead to complete takeover of the platform's admin account. Organizations using affected versions should prioritize patching to version 1.11.40 or later to mitigate this critical risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser session, leading to full platform admin account takeover. This has been patched in 1.11.40.