PT-2026-32933 · Unknown · Chamilo Lms
Aastha2602
·
Published
2026-04-14
·
Updated
2026-04-15
·
CVE-2026-34602
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Chamilo LMS versions prior to 2.0.0-RC.3
Description
An Insecure Direct Object Reference (IDOR) exists in the '/api/course rel users' endpoint. An authenticated attacker can modify the
user parameter in the request body to enroll any arbitrary user into any course. This occurs because the backend trusts user-supplied input for the user field without server-side verification to ensure the requester has the necessary permissions to act on behalf of other users. This allows unauthorized manipulation of user-course relationships, which can lead to bypassing enrollment controls and granting unintended access to course materials.Recommendations
Update to version 2.0.0-RC.3.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chamilo Lms