PT-2026-3305 · Unknown · Chamilo Lms

Published

2026-01-16

·

Updated

2026-02-05

·

CVE-2025-69581

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Chamillo LMS version 1.11.2
Description The Social Network /personal data API endpoint in Chamillo LMS does not implement proper cache control, leading to exposure of full sensitive user information even after logout. Utilizing the browser back button allows unauthorized users on the same device to view confidential information, potentially resulting in profiling, impersonation, and targeted attacks. The issue poses significant privacy risks. The vulnerable API endpoint is /personal data.
Recommendations Apply appropriate cache-control headers to the /personal data API endpoint to prevent sensitive data from being cached and accessible after logout.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-69581

Affected Products

Chamilo Lms