Critical XSS Vulnerability in Chamilo LMS Leads to Admin Account Takeover
ID: 79ee0855-ca57-56a3-96ac-c41785c060bf
STIX ID: report--79ee0855-ca57-56a3-96ac-c41785c060bf
Feed Name: ThreatCluster
Threat Score
A critical stored XSS vulnerability (CVE-2026-39878, CVSS 9.3) affecting Chamilo LMS versions 1.11.38 and earlier allows unauthenticated attackers to execute JavaScript in administrator sessions and potentially achieve full platform admin account takeover; public exploits exist and users are urged to upgrade to 1.11.40 where a patch is available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
