Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 12 Sep 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chamilo
Chamilo chamilo Lms |
|
| Vendors & Products |
Chamilo
Chamilo chamilo Lms |
Fri, 11 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Chamilo LMS before 1.11.42 and 3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious script payloads into survey answers by computing deterministic invitation codes and bypassing authorization checks in the survey submission endpoint. Attackers can submit crafted answers containing unescaped HTML rendered in reporting views to execute arbitrary scripts in the browser sessions of teachers or administrators, enabling persistent backdoor account creation by exploiting the victim's authenticated session. | |
| Title | Chamilo LMS Stored XSS via Survey Answer Submission in reporting.php | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-11T19:21:27.326Z
Reserved: 2026-08-29T17:20:57.083Z
Link: CVE-2026-82535
Updated: 2026-09-11T19:21:19.922Z
Status : Received
Published: 2026-09-11T18:16:59.290
Modified: 2026-09-11T20:19:15.857
Link: CVE-2026-82535
No data.
OpenCVE Enrichment
Updated: 2026-09-12T22:00:07Z