Missing Authorization in Chamilo LMS - CVE-2026-62305
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to modify application data.
The vulnerability exists due to missing authorization in /template/document-templates/{documentId}/delete endpoint when handling delete requests for document templates. A remote attacker can send a crafted request to modify application data.
The issue can be exploited without authentication to delete document templates, modify template associations, and alter course content configuration.