Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the session category management section.
chamilo chamilo