PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45143 chamilo CVE debrief

CVE-2026-45143 Chamilo LMS Message Content Stored Cross-Site Scripting. An authenticated low-privilege user can craft message content that executes in an administrator's browser when viewed, potentially exposing session credentials or allowing actions as the administrator. The issue is fixed in version 2.0.1. Reviewing and updating to this version is recommended. This vulnerability is critical, with a CVSS score of 9, and administrators should prioritize patching and updates to mitigate this vulnerability.

Vendor
chamilo
Product
chamilo-lms
CVSS
CRITICAL 9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-17
Original CVE updated
2026-09-29
Advisory published
2026-09-17
Advisory updated
2026-09-29

Who should care

Administrators and users of Chamilo LMS, particularly those with low-privilege accounts, should be aware of this vulnerability and take steps to mitigate it. Reviewing and updating to version 2.0.1 or later is recommended.

Why it matters

CVE-2026-45143 is a critical vulnerability in Chamilo LMS that allows an authenticated low-privilege user to craft message content that can execute in the browser of an administrator. This could lead to exposure of session credentials or allow actions as the administrator. The issue is fixed in version 2.0.1, and administrators should prioritize patching and updates to mitigate this vulnerability.

  • Potential exposure of session credentials
  • Possible actions as an administrator
  • Verification of user input sanitization
  • Prioritization of patching and updates

Technical summary

The Chamilo LMS is vulnerable to stored cross-site scripting (XSS) in the message content. An authenticated low-privilege user can craft message content that executes in the browser of an administrator when the message is viewed, potentially exposing session credentials or allowing actions as the administrator. The issue is fixed in version 2.0.1. The vulnerability allows for the execution of arbitrary JavaScript code in the context of the administrator's session, which could lead to unauthorized actions or data exposure. Administrators should review and update Chamilo LMS to version 2.0.1 or later to mitigate this vulnerability.

Defensive priority

High

Recommended defensive actions

  • Review and update Chamilo LMS to version 2.0.1 or later
  • Restrict message content creation and editing to trusted users
  • Monitor user activity and message content for suspicious behavior
  • Implement additional security measures to protect against cross-site scripting attacks
  • Verify user input sanitization for message content
  • Prioritize patching and updates for Chamilo LMS
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record and NVD entry provide details on the Chamilo LMS vulnerability. The vulnerability allows an authenticated low-privilege user to craft message content that can execute in the browser of an administrator when the message is viewed, potentially exposing session credentials or allowing actions as the administrator. The issue is fixed in version 2.0.1.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-45143 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-45143

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-45143 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45143

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.