Insecure Direct Object Reference in Chamilo LMS Notebook Module
CVE-2026-34370
6.5MEDIUM
What is CVE-2026-34370?
Chamilo LMS, an open-source learning management system, features a critical vulnerability in its notebook module found in versions prior to 2.0.0-RC.3. This Insecure Direct Object Reference (IDOR) flaw allows authenticated students to access and read private course notes of other users by altering the notebook_id parameter during the editnote action. The application inadequately verifies user ownership when accessing notes, leading to potential unauthorized data exposure. The vulnerability has been addressed in the latest version, ensuring that ownership checks are enforced during read operations.
Affected Version(s)
chamilo-lms < 2.0.0-RC.3
