CVE-2025-52475 | Chamilo LMS up to 1.11.29 admin/user_list.php keyword_inactive cross site scripting (EUVD-2025-208176)
A vulnerability marked as problematic has been reported in Chamilo LMS up to 1.11.29. This impacts an unknown function of the file admin/user_list.php. The manipulation of the argument keyword_inactive leads to cross site scripting.
This vulnerability is documented as CVE-2025-52475. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.