Authorization Flaw in Chamilo Learning Management System
CVE-2025-59544

6.9MEDIUM

Key Information:

Vendor

Chamilo

Vendor
CVE Published:
6 March 2026

What is CVE-2025-59544?

Chamilo, a learning management system, reveals a significant flaw prior to version 1.11.34 where the absence of proper authorization checks on the 'category_id' parameter allows users to change the category of any user. This loophole enables unauthorized manipulation of user categories, posing a potential risk to user confidentiality and system integrity. The vulnerability has been addressed in version 1.11.34, where the necessary authorization checks have been implemented to safeguard against such unauthorized updates.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

chamilo-lms < 1.11.34

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.