Authorization bypass through user-controlled key in Chamilo LMS - CVE-2026-62307
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and copy private course resources.
The vulnerability exists due to authorization bypass through a user-controlled key in the Course Maintenance copy endpoints when handling a user-supplied sourceCourseId. A remote user can supply an arbitrary course code as the source course identifier to disclose sensitive information and copy private course resources.
Exploitation requires access to any destination course.