{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-10T18:15:32.206","vulnerabilities":[{"cve":{"id":"CVE-2025-55208","sourceIdentifier":"security-advisories@github.com","published":"2026-03-05T21:16:13.447","lastModified":"2026-03-09T20:20:00.163","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `Social Networks`. Through it, a low-privilege user can execute arbitrary code in the admin user inbox, allowing takeover of the admin account. Version 1.11.34 fixes the issue."},{"lang":"es","value":"Chamilo es un sistema de gestión del aprendizaje. Las versiones anteriores a la 1.11.34 tienen un XSS Almacenado a través de cargas de archivos inseguras en 'Redes Sociales'. A través de ello, un usuario con pocos privilegios puede ejecutar código arbitrario en la bandeja de entrada del usuario administrador, permitiendo la toma de control de la cuenta de administrador. La versión 1.11.34 corrige el problema."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","baseScore":9.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":6.0}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:*","versionEndExcluding":"1.11.34","matchCriteriaId":"BF6714C4-3D58-43BF-A32C-6D436DB93E01"}]}]}],"references":[{"url":"https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-2vq2-826h-6hp6","source":"security-advisories@github.com","tags":["Vendor Advisory"]}]}}]}