logo

Critical XSS Vulnerability in Chamilo LMS Leads to Admin Account Takeover

ID: 79ee0855-ca57-56a3-96ac-c41785c060bf

STIX ID: report--79ee0855-ca57-56a3-96ac-c41785c060bf

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

...
...

A critical stored XSS vulnerability (CVE-2026-39878, CVSS 9.3) affecting Chamilo LMS versions 1.11.38 and earlier allows unauthenticated attackers to execute JavaScript in administrator sessions and potentially achieve full platform admin account takeover; public exploits exist and users are urged to upgrade to 1.11.40 where a patch is available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.