CVE-2025-52482 - CERT CVE
ID CVE-2025-52482
Sažetak Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teachers role to inject JavaScript malicious code against the administrator. This issue has been patched in version 1.11.30.
Reference
CVSS
Base: 8.3
Impact: 6.0
Exploitability:1.7
Pristup
VektorSloženostAutentikacija
NETWORK LOW HIGH
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH LOW
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L
Zadnje važnije ažuriranje 03-03-2026 - 19:13
Objavljeno 02-03-2026 - 15:16