CVE-2026-33704
- EPSS 0.42%
- Veröffentlicht 10.04.2026 18:30:48
- Zuletzt bearbeitet 16.04.2026 18:34:15
Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including students) can write arbitrary content to files on the server via the BigUpload endpoint. The key parameter controls the filename and the raw POST body be...
CVE-2026-33703
- EPSS 0.17%
- Veröffentlicht 10.04.2026 18:23:01
- Zuletzt bearbeitet 16.04.2026 18:48:04
Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the /social-network/personal-data/{userId} endpoint allows any authenticated user to access full personal data and API token...
CVE-2026-33702
- EPSS 0.24%
- Veröffentlicht 10.04.2026 18:15:49
- Zuletzt bearbeitet 16.04.2026 18:48:21
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an Insecure Direct Object Reference (IDOR) vulnerability in the Learning Path progress saving endpoint. The file lp_ajax_save_item.php accepts a uid (u...
CVE-2026-33698
- EPSS 0.32%
- Veröffentlicht 10.04.2026 18:14:17
- Zuletzt bearbeitet 16.04.2026 18:48:33
Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated attacker to modify existing files or create new files where allowed by...
CVE-2026-33618
- EPSS 0.32%
- Veröffentlicht 10.04.2026 18:10:16
- Zuletzt bearbeitet 17.04.2026 22:03:07
Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController::decodeSettingArray() method uses PHP's eval() to parse platform settings from the database. An attacker with admin access (obtainable via Advisory 1...
CVE-2026-33141
- EPSS 0.14%
- Veröffentlicht 10.04.2026 18:01:26
- Zuletzt bearbeitet 17.04.2026 21:24:02
Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the REST API stats endpoint allows any authenticated user (including low-privilege students with ROLE_USER) to read any othe...
CVE-2026-32892
- EPSS 1.53%
- Veröffentlicht 10.04.2026 17:56:57
- Zuletzt bearbeitet 17.04.2026 21:30:50
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move function. The move() function in fileManage.lib.php passes user-controlled path values directly ...
CVE-2026-32932
- EPSS 0.18%
- Veröffentlicht 10.04.2026 17:51:58
- Zuletzt bearbeitet 17.04.2026 21:27:32
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Open Redirect vulnerability in the session course edit page allows an attacker to redirect an authenticated administrator to an arbitrary external URL after saving coach...
CVE-2026-32931
- EPSS 0.5%
- Veröffentlicht 10.04.2026 17:50:40
- Zuletzt bearbeitet 17.04.2026 21:27:59
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file upload vulnerability in the exercise sound upload function allows an authenticated teacher to upload a PHP webshell by spoofing the Content-Type header...
CVE-2026-32930
- EPSS 0.19%
- Veröffentlicht 10.04.2026 17:48:51
- Zuletzt bearbeitet 17.04.2026 21:28:36
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebook evaluation edit page allows any authenticated teacher to view and modify the settings (name, max s...