Authorization Flaw in Chamilo Learning Management System
CVE-2025-59544
6.9MEDIUM
What is CVE-2025-59544?
Chamilo, a learning management system, reveals a significant flaw prior to version 1.11.34 where the absence of proper authorization checks on the 'category_id' parameter allows users to change the category of any user. This loophole enables unauthorized manipulation of user categories, posing a potential risk to user confidentiality and system integrity. The vulnerability has been addressed in version 1.11.34, where the necessary authorization checks have been implemented to safeguard against such unauthorized updates.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
chamilo-lms < 1.11.34
