XML External Entity injection in Chamilo LMS - CVE-2026-61658
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper restriction of xml external entity reference in the user import endpoint when parsing uploaded XML files. A remote privileged user can upload a specially crafted XML file to disclose sensitive information.
Successful exploitation can expose arbitrary local files from the server filesystem, including configuration files containing database credentials.