A stored cross-site scripting (XSS) vulnerability exists in the message compose feature of Chamilo LMS version 1.11.28. Attackers can inject malicious JavaScript code into messages. When a victim, such as an administrator, replies to the message, the injected script is executed in their browser context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a small PoC for CVE-2025-26153 affecting Chamilo LMS <= 2.0: a stored XSS in forum/social group thread titles that can be chained into privilege escalation. Structure: - README.md: Walkthrough of the attack chain, vulnerable rendering locations (e.g., /public/main/forum/forumqualify.php and /public/main/forum/viewforum.php), and an example XSS snippet that loads external JS. Includes sample console output from a CTF instance. - generate_payload.py: Interactive Python generator that writes payload.js. The generated JavaScript is intended to be hosted externally and loaded by the stored XSS. Exploit chain/capabilities: 1) Attacker injects stored XSS in a thread title (e.g., <img onerror=...> or <script src=...>). 2) When an administrator views the thread, the browser loads attacker-hosted payload.js. 3) payload.js creates a hidden multipart/form-data form targeting /main/admin/user_edit.php?user_id=<target> and sets platform_admin=1 (plus many other fields to mimic a captured legitimate request). It auto-submits the form using the admin’s cookies (and also attempts a fetch POST with credentials: 'include'). 4) Result: the specified user_id is promoted to platform administrator; optional profile changes (username/email/official_code, optional password) are supported via generator inputs. Notable targeting details: - Primary privilege escalation endpoint: /main/admin/user_edit.php?user_id=<uid> (POST). - Second-stage payload delivery relies on an attacker-controlled external URL (scheme-relative //.../payload.js). Overall, this is an operational PoC (not a scanner): it provides a working second-stage payload generator and clear manual steps to trigger stored XSS and leverage the admin session to elevate privileges.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.