CVE-2025-52476 | Chamilo LMS up to 1.11.29 admin/user_list.php keyword_active cross site scripting (EUVD-2025-208177)
A vulnerability described as problematic has been identified in Chamilo LMS up to 1.11.29. Affected is an unknown function of the file admin/user_list.php. The manipulation of the argument keyword_active results in cross site scripting.
This vulnerability is reported as CVE-2025-52476. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.