PT-2026-32023 · Unknown · Chamilo Lms

CVE-2026-33708

·

Published

2026-04-10

·

Updated

2026-04-10

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Chamilo LMS versions prior to 1.11.38
Description Chamilo LMS is a learning management system. The get user info from username API endpoint ('/get user info from username') does not perform authorization checks, allowing any authenticated user to retrieve personal information (email, first name, last name, user ID, active status) of any other user. The vulnerable parameter is the username.
Recommendations Update to version 1.11.38 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33708
GHSA-QWCH-82Q9-Q999

Affected Products

Chamilo Lms