Exposed Twig Template Files in Chamilo LMS by Chamilo
CVE-2026-33705

5.3MEDIUM

Key Information:

Vendor

Chamilo

Vendor
CVE Published:
10 April 2026

What is CVE-2026-33705?

Chamilo LMS, a widely used learning management system, has a vulnerability where Twig template files located at /main/template/default/ are exposed to public access without authentication. This flaw can be exploited via HTTP GET requests, potentially disclosing crucial internal application logic, variable names, AJAX endpoint URLs, and the structure of the admin panel. The vulnerability was addressed in version 1.11.38, enhancing the platform's security against unauthorized data exposure.

Affected Version(s)

chamilo-lms < 1.11.38

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.