Insecure Direct Object Reference in Chamilo LMS Notebook Module
CVE-2026-34370

6.5MEDIUM

Key Information:

Vendor

Chamilo

Vendor
CVE Published:
14 April 2026

What is CVE-2026-34370?

Chamilo LMS, an open-source learning management system, features a critical vulnerability in its notebook module found in versions prior to 2.0.0-RC.3. This Insecure Direct Object Reference (IDOR) flaw allows authenticated students to access and read private course notes of other users by altering the notebook_id parameter during the editnote action. The application inadequately verifies user ownership when accessing notes, leading to potential unauthorized data exposure. The vulnerability has been addressed in the latest version, ensuring that ownership checks are enforced during read operations.

Affected Version(s)

chamilo-lms < 2.0.0-RC.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.