PT-2026-32003 · Unknown · Chamilo Lms

CVE-2026-32894

·

Published

2026-04-10

·

Updated

2026-04-11

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Chamilo LMS versions prior to 1.11.38 Chamilo LMS versions prior to 2.0.0-RC.3
Description Chamilo LMS contains an Insecure Direct Object Reference (IDOR) issue in the gradebook result view page. An authenticated teacher can delete any student's grade result by manipulating the delete mark or resultdelete GET parameters. There is no ownership or course-scope verification performed.
Recommendations Update to version 1.11.38 or later. Update to version 2.0.0-RC.3 or later.

Exploit

Fix

NULL Pointer Dereference

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32894
GHSA-RQPG-P95V-FV98

Affected Products

Chamilo Lms