XML External Entity injection in Chamilo LMS - CVE-2026-61658

 

XML External Entity injection in Chamilo LMS - CVE-2026-61658

Published: August 4, 2026


Vulnerability identifier: #VU140907
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2026-61658
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper restriction of xml external entity reference in the user import endpoint when parsing uploaded XML files. A remote privileged user can upload a specially crafted XML file to disclose sensitive information.

Successful exploitation can expose arbitrary local files from the server filesystem, including configuration files containing database credentials.


Affected software

Chamilo LMS

How to mitigate CVE-2026-61658

Install security update from vendor's website.

Chamilo LMS - update to 2.0.3

External References