Support Us — Your donation helps us keep running

Goal: 1000 CNY,Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2025-52469
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Chamilo: Friend Request Workflow Bypass - Unauthorized Friend Addition and ID Validation Bypass
Source: NVD (National Vulnerability Database)
Vulnerability Description
Chamilo is a learning management system. Prior to version 1.11.30, a logic vulnerability in the friend request workflow of Chamilo’s social network module allows an authenticated user to forcibly add any user as a friend by directly calling the AJAX endpoint. The attacker can bypass the normal flow of sending and accepting friend requests, and even add non-existent users. This breaks access control and social interaction logic, with potential privacy implications. This issue has been patched in version 1.11.30.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
行为工作流的不恰当实施
Source: NVD (National Vulnerability Database)
Vulnerability Title
Chamilo 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Chamilo是Chamilo开源的一个学习管理系统。 Chamilo 1.11.30之前版本存在安全漏洞,该漏洞源于社交网络模块的好友请求工作流存在逻辑缺陷,可能导致经过身份验证的用户绕过正常流程强制添加好友。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
chamilochamilo-lms < 1.11.30 -
II. Public POCs for CVE-2025-52469
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2025-52469
Please Login to view more intelligence information
New Vulnerabilities
V. Comments for CVE-2025-52469

No comments yet


Leave a comment