Missing Authorization in Chamilo LMS - CVE-2026-62306
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to modify application data.
The vulnerability exists due to missing authorization in the /template/document-templates/create endpoint when handling template creation and document modification requests. A remote attacker can send a crafted request to modify application data.
The issue can be exploited to create document templates, alter template associations, and mark arbitrary documents as templates.