External risk intelligence

Chamilo LMS Message Content Cross-Site Scripting Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2026-45143

Chamilo is a web-based learning management system designed for remote access by students and administrators over the internet. As a web application accessible to authenticated users in typical deployments, its messaging features are frequently exposed to the public internet, making this application layer surface commonly reachable.

Cross-site Scripting

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Chamilo LMS, an open-source learning management system, allows authenticated low-privilege users to potentially execute malicious code within an administrator's browser by sending specially crafted messages. This could expose sensitive session information or allow unauthorized actions.

  • Low-privilege users can compromise administrator sessions.
  • Impacts learning platforms used by many.
  • Confirm relevance and exposure of the system.

Attack Path

How an attacker could exploit the issue

An attacker with low-level access, like a student, can send a crafted message to an administrator. When the administrator views the message, the malicious content executes in their browser, potentially leading to the exposure of session credentials or unauthorized actions.

  • Authenticated user, low privilege
  • Crafted message content rendered as HTML
  • Session theft or administrator actions

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could impact the privacy of private messages and compromise administrator sessions within Chamilo LMS. An authenticated, low-privilege user can craft a message containing malicious HTML. When an administrator views this message, the crafted content executes in their browser, potentially exposing session credentials or allowing unauthorized actions.

  • Private message content.
  • Crafted message execution in browser.
  • Administrator session compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

In real-world scenarios, the Chamilo LMS administrator or the IT team responsible for managing the learning management system would likely own this issue. The first practical step is to identify all Chamilo LMS instances, confirm their reachability and business criticality, and then determine the accountable owner for remediation planning.

  • Platform/Application owners
  • Verify all Chamilo instances deployed.
  • Plan for vendor coordinated update.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Chamilo LMS?

Chamilo LMS is an open-source learning management system that facilitates digital education. It allows administrators to organize courses and provides students with a portal for learning activities, including direct communication features like internal messaging.

What is the vulnerability in CVE-2026-45143?

This vulnerability is a Cross-Site Scripting (CWE-79) issue. It occurs because the system fails to clean message content before displaying it. When a user sends a message containing malicious HTML, the application treats it as active code rather than plain text, allowing it to run inside the recipient's browser.

How does the message content trigger this security issue?

A sender triggers the bug by including malicious code in a message addressed to an administrator. The vulnerability activates automatically when the administrator opens their inbox to view the message. It is not triggered by viewing standard, non-malicious messages or by simply being logged into the platform.

Is my Chamilo instance at risk?

According to Halo Surface Signal, Chamilo is typically deployed for remote access, making its messaging features commonly reachable over the public internet. If your instance is internet-facing and allows student accounts to send messages, it faces a higher level of exposure to this specific attack path.

What should I do if I run Chamilo LMS?

Begin by identifying all active Chamilo installations within your environment. Once you have a complete inventory, verify the version currently in use and coordinate with your technical team to plan an update to version 2.0.1 or later to resolve this vulnerability.

References