PT-2026-32916 · Unknown · Chamilo Lms

·

CVE-2026-34160

·

Published

2026-04-14

·

Updated

2026-04-15

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Chamilo LMS versions prior to 2.0.0-RC.3
Description The PENS (Package Exchange Notification Services) plugin endpoint ''public/plugin/Pens/pens.php'' is accessible without authentication. It accepts a user-controlled package-url parameter that the server fetches using curl without filtering private or internal IP addresses, enabling Server-Side Request Forgery (SSRF). SSRF is a flaw that allows an attacker to induce the server-side application to make requests to an unexpected destination. An attacker can use this to probe internal network services, access cloud metadata endpoints to steal IAM credentials and sensitive instance metadata, or trigger state-changing operations on internal services via the receipt and alerts callback parameters.
Recommendations Update to version 2.0.0-RC.3.

Exploit

Fix

Missing Authentication

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34160
GHSA-G2XJ-4CCH-J276

Affected Products

Chamilo Lms