LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2025-59541

CVE-2025-59541 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: March 6, 2026

Chamilo - Cross-Site Request Forgery

Published: March 6, 2026Updated: March 6, 2026Remote Exploitable

Overview

Chamilo < 1.11.34 contains a cross-site request forgery caused by missing anti-CSRF tokens on project deletion actions, letting attackers trick authenticated trainers into deleting projects without consent, exploit requires user interaction.

Severity & Score

Severity: High
CVSS Score: 8.1
EPSS Score: 1.5%(Probability of exploitation in next 30 days)

Impact

Attackers can trick authenticated trainers into deleting projects, causing data loss and disruption.

Mitigation

Update to version 1.11.34 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 6, 2026

🟠 CVE-2025-59541 - High (8.1) Chamilo is a learning management system. Prior to version 1.11.34, a Cross-Site Request Forgery (CSRF) vulnerability allows an attacker to delete projects inside a course without the victim’s consent. The issue arises because sensitive actions s... 🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-59541/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 6, 2026

🟠 CVE-2025-59541 - High (8.1) Chamilo is a learning management system. Prior to version 1.11.34, a Cross-Site Request Forgery (CSRF) vulnerability allows an attacker to delete projects inside a course without the victim’s consent. The issue arises because sensitive actions s... 🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-59541/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2025-59541
Severity
High
CVSS Score
8.1
Type
cross_site_request_forgery
Status
new
EPSS
1.5%
Social Posts
2

CWE

  • CWE-352

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

EPSS Score

1.5%Probability of exploitation in the next 30 days