User Information Leak in Chamilo LMS Learning Management System
CVE-2026-33708
6.5MEDIUM
What is CVE-2026-33708?
Chamilo LMS, a widely-used learning management system, has a vulnerability in the get_user_info_from_username REST API endpoint, which allows authenticated users, including students, to access sensitive personal information of any other user without proper authorization checks. This information includes email addresses, first and last names, user IDs, and active status. Such exposure can lead to privacy violations and potential misuse of user data. The issue has been addressed in version 1.11.38, where necessary security measures have been implemented to restrict access to personal information.
Affected Version(s)
chamilo-lms < 1.11.38
