CVE-2024-30618: Chamilo Lms

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web browser by including a malicious payload in the 'content' parameter of 'group_topics.php'.

Affected products

  • Chamilo Chamilo Lms: version 1.11.26 only

Published 2024-11-04. Last modified 2026-06-17.