PT-2026-32025 · Unknown · Chamilo Lms

Published

2026-04-10

·

Updated

2026-04-10

·

CVE-2026-33736

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Chamilo LMS versions prior to 2.0.0-RC.3
Description Chamilo LMS is a learning management system. Any authenticated user, including those with the ROLE STUDENT role, can enumerate all platform users and access personal information such as email, phone number, and roles via the /api/users API endpoint. This includes access to administrator accounts.
Recommendations Update to version 2.0.0-RC.3 or later.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-33736

Affected Products

Chamilo Lms