CVE-2025-52470 | Chamilo LMS up to 1.11.29 session_category_add.php Category Name cross site scripting
A vulnerability labeled as problematic has been found in Chamilo LMS up to 1.11.29. This affects an unknown function of the file session_category_add.php. Executing a manipulation of the argument Category Name can lead to cross site scripting.
This vulnerability is registered as CVE-2025-52470. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.