PT-2026-32003 · Chamilo · Chamilo Lms

Published

2026-04-10

·

Updated

2026-04-10

·

CVE-2026-32894

CVSS v3.1

7.1

High

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebook result view page allows any authenticated teacher to delete any student's grade result across the entire platform by manipulating the delete mark or resultdelete GET parameters. No ownership or course-scope verification is performed. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.

Fix

NULL Pointer Dereference

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-32894

Affected Products

Chamilo Lms