Server-Side Request Forgery (SSRF) in Chamilo LMS - CVE-2026-34160
Published: April 24, 2026
Chamilo LMS
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to server-side request forgery (SSRF) in the PENS plugin endpoint at public/plugin/Pens/pens.php when processing user-controlled package-url, receipt, and alerts parameters. A remote attacker can send a specially crafted request to disclose sensitive information.
In cloud environments, exploitation can reach instance metadata services and expose credentials or identity tokens.