LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2025-52482

CVE-2025-52482 - Vulnerability Analysis

HighCVSS: 8.3

Last Updated: March 3, 2026

Chamilo - Stored XSS

Published: March 2, 2026Updated: March 3, 2026PoC AvailableRemote Exploitable

Overview

Chamilo < 1.11.30 contains a stored XSS caused by improper sanitization in the glossary function, letting users with Teachers role inject malicious JavaScript against administrators, exploit requires Teacher role.

Severity & Score

Severity: High
CVSS Score: 8.3
EPSS Score: 3.8%(Probability of exploitation in next 30 days)

Impact

Attackers with Teacher role can execute malicious JavaScript in administrator's browser, potentially leading to session hijacking or further attacks.

Mitigation

Update to version 1.11.30 or later.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 2, 2026

🟠 CVE-2025-52482 - High (8.3) Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teachers role to inject JavaScript malicious code against the administrator. This issue has ... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2025-52482/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2025-52482
Severity
High
CVSS Score
8.3
Type
stored_xss
Status
confirmed
EPSS
3.8%
Social Posts
1

CWE

  • CWE-79

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L

EPSS Score

3.8%Probability of exploitation in the next 30 days