Chamilo Learning Management System HTML Injection Vulnerability in help.php

Vulnerability

A vulnerability allowing HTML injection has been identified in Chamilo Learning Management System versions prior to 1.11.30. The issue arises in the help.php file, where the open parameter is not properly sanitized, enabling attackers to inject arbitrary HTML, such as underlined text, through a crafted URL. This vulnerability has been addressed in version 1.11.30.

Impact

Exploitation of this vulnerability allows for HTML injection, which could be leveraged for cross-site scripting (XSS) attacks, as confirmed by the vulnerability reporter.

Reproduction

To reproduce this vulnerability, send a request to the help.php file with a crafted URL that includes an unescaped HTML tag, such as an underline tag. The injected HTML will be rendered, demonstrating the successful exploitation of the vulnerability.

Remediation

Users can upgrade to Chamilo version 1.11.30 or later, where this vulnerability has been patched.

Added: Mar 2, 2026, 4:26 PM
Updated: Mar 2, 2026, 9:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
0.2
exploitability
7.5
remediation
7.7
relevance
3.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.