Vulnerability Description
Chamilo LMS is a learning management system. From 1.11.0 to 2.0-beta.1, anyone can trigger a malicious redirect through the use of the redirect parameter to /login. This vulnerability is fixed in 2.0-beta.2.
CVSS Score
NONE
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chamilo | Chamilo Lms | <= 1.11.38 |
Related Weaknesses (CWE)
References
- https://github.com/chamilo/chamilo-lms/commit/73ae6293adaa6098374bc22625342dbae5Patch
- https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-m82x-prv3-rwwvVendor Advisory
FAQ
What is CVE-2025-66447?
CVE-2025-66447 is a vulnerability with a CVSS score of 0.0 (NONE). Chamilo LMS is a learning management system. From 1.11.0 to 2.0-beta.1, anyone can trigger a malicious redirect through the use of the redirect parameter to /login. This vulnerability is fixed in 2.0-...
How severe is CVE-2025-66447?
CVE-2025-66447 has been rated NONE with a CVSS base score of 0.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-66447?
Check the references section above for vendor advisories and patch information. Affected products include: Chamilo Chamilo Lms.