CVE-2024-51142: Chamilo Lms

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.php file.

Affected products

  • Chamilo Chamilo Lms: version 1.11.26 only

Published 2024-11-15. Last modified 2026-06-17.