The Null Byte That Walked Past HTMLPurifier: CVE-2026-39878 in Chamilo LMS
A single null byte hidden inside an event handler slipped a live XSS payload past HTMLPurifier at sign-up. An unescaped admin user list did the rest. An unauthenticated attacker could register an account and take over the platform administrator's session. CVSS 9.3 Critical.
Read More