User Information Leak in Chamilo LMS Learning Management System
CVE-2026-33708

6.5MEDIUM

Key Information:

Vendor

Chamilo

Vendor
CVE Published:
10 April 2026

What is CVE-2026-33708?

Chamilo LMS, a widely-used learning management system, has a vulnerability in the get_user_info_from_username REST API endpoint, which allows authenticated users, including students, to access sensitive personal information of any other user without proper authorization checks. This information includes email addresses, first and last names, user IDs, and active status. Such exposure can lead to privacy violations and potential misuse of user data. The issue has been addressed in version 1.11.38, where necessary security measures have been implemented to restrict access to personal information.

Affected Version(s)

chamilo-lms < 1.11.38

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.