CVE-2026-33141
- EPSS 0.02%
- Veröffentlicht 10.04.2026 18:01:26
- Zuletzt bearbeitet 17.04.2026 21:24:02
Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the REST API stats endpoint allows any authenticated user (including low-privilege students with ROLE_USER) to read any othe...
CVE-2026-32892
- EPSS 0.19%
- Veröffentlicht 10.04.2026 17:56:57
- Zuletzt bearbeitet 17.04.2026 21:30:50
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move function. The move() function in fileManage.lib.php passes user-controlled path values directly ...
CVE-2026-32932
- EPSS 0.03%
- Veröffentlicht 10.04.2026 17:51:58
- Zuletzt bearbeitet 17.04.2026 21:27:32
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Open Redirect vulnerability in the session course edit page allows an attacker to redirect an authenticated administrator to an arbitrary external URL after saving coach...
CVE-2026-32931
- EPSS 0.16%
- Veröffentlicht 10.04.2026 17:50:40
- Zuletzt bearbeitet 17.04.2026 21:27:59
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file upload vulnerability in the exercise sound upload function allows an authenticated teacher to upload a PHP webshell by spoofing the Content-Type header...
CVE-2026-32930
- EPSS 0.03%
- Veröffentlicht 10.04.2026 17:48:51
- Zuletzt bearbeitet 17.04.2026 21:28:36
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebook evaluation edit page allows any authenticated teacher to view and modify the settings (name, max s...
CVE-2026-32894
- EPSS 0.03%
- Veröffentlicht 10.04.2026 17:44:24
- Zuletzt bearbeitet 17.04.2026 21:28:56
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebook result view page allows any authenticated teacher to delete any student's grade result across the ...
CVE-2026-32893
- EPSS 0.03%
- Veröffentlicht 10.04.2026 17:42:24
- Zuletzt bearbeitet 17.04.2026 21:30:03
Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, a Reflected Cross-Site Scripting (XSS) vulnerability in the exercise question list admin panel allows an attacker to execute arbitrary JavaScript in an authenticated teacher's browser....
CVE-2026-31941
- EPSS 0.03%
- Veröffentlicht 10.04.2026 17:37:50
- Zuletzt bearbeitet 17.04.2026 21:31:11
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains a Server-Side Request Forgery (SSRF) vulnerability in the Social Wall feature. The endpoint read_url_with_open_graph accepts a URL from the user via th...
CVE-2026-31940
- EPSS 0.04%
- Veröffentlicht 10.04.2026 17:35:10
- Zuletzt bearbeitet 17.04.2026 21:31:36
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.php, user-controlled request parameters are directly used to set the PHP session ID before loading global bootstrap. This leads to session fixation. Th...
CVE-2026-31939
- EPSS 0.04%
- Veröffentlicht 10.04.2026 17:32:29
- Zuletzt bearbeitet 17.04.2026 21:23:42
Chamilo LMS is a learning management system. Prior to 1.11.38, there is a path traversal in main/exercise/savescores.php leading to arbitrary file feletion. User input from $_REQUEST['test'] is concatenated directly into filesystem path without canon...