PT-2026-32003 · Unknown · Chamilo Lms

Published

2026-04-10

·

Updated

2026-04-11

·

CVE-2026-32894

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Chamilo LMS versions prior to 1.11.38 Chamilo LMS versions prior to 2.0.0-RC.3
Description Chamilo LMS contains an Insecure Direct Object Reference (IDOR) issue in the gradebook result view page. An authenticated teacher can delete any student's grade result by manipulating the delete mark or resultdelete GET parameters. There is no ownership or course-scope verification performed.
Recommendations Update to version 1.11.38 or later. Update to version 2.0.0-RC.3 or later.

Exploit

Fix

IDOR

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2026-32894

Affected Products

Chamilo Lms