PT-2026-3374 · Unknown · Chamilo Lms

Angelkate

·

Publicado

2026-01-18

·

Atualizado

2026-01-18

·

CVE-2026-1106

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Chamilo LMS versions up to 2.0.0 Beta 1
Description A security flaw exists in Chamilo LMS that allows for remote unauthorized access due to improper authorization. The issue is located within the deleteLegal function of the Legal Consent Handler component, specifically in the file src/CoreBundle/Controller/SocialController.php. Manipulation of the userId argument can lead to unauthorized actions. The exploit for this issue has been publicly released.
Recommendations Versions prior to 2.0.0 Beta 1 should be used. As a temporary workaround, consider restricting access to the deleteLegal() function until a patch is available.

Exploit

Correção

Improper Authorization

Incorrect Privilege Assignment

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1106

Produtos afetados

Chamilo Lms