Improperly Controlled Modification of Dynamically-Determined Object Attributes in Chamilo LMS - CVE-2026-61785
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in registration.php and UserManager::create_user() when processing self-registration requests. A remote attacker can submit a crafted status field during registration to escalate privileges.
User interaction is required to complete registration, and the issue can assign the session administrator or HR role instead of the intended student or teacher role.