PT-2026-3305 · Unknown · Chamilo Lms
Published
2026-01-16
·
Updated
2026-02-05
·
CVE-2025-69581
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Chamillo LMS version 1.11.2
Description
The Social Network
/personal data API endpoint in Chamillo LMS does not implement proper cache control, leading to exposure of full sensitive user information even after logout. Utilizing the browser back button allows unauthorized users on the same device to view confidential information, potentially resulting in profiling, impersonation, and targeted attacks. The issue poses significant privacy risks. The vulnerable API endpoint is /personal data.Recommendations
Apply appropriate cache-control headers to the
/personal data API endpoint to prevent sensitive data from being cached and accessible after logout.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Chamilo Lms