Cross-site request forgery in Chamilo LMS - CVE-2026-61656

 

Cross-site request forgery in Chamilo LMS - CVE-2026-61656

Published: August 4, 2026


Vulnerability identifier: #VU140908
CSH Severity: High
CVSS v4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-61656
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to manipulate student grades and evaluation data.

The vulnerability exists due to cross-site request forgery in the Gradebook module endpoints responsible for managing evaluations and grades when handling crafted GET requests without proper anti-CSRF token validation. A remote attacker can trick a victim into visiting a maliciously crafted webpage to manipulate student grades and evaluation data.

User interaction is required, and exploitation targets authenticated administrator, teacher, or course coach sessions.


Affected software

Chamilo LMS

How to mitigate CVE-2026-61656

Install security update from vendor's website.

Chamilo LMS - addressed in versions 1.11.40, 2.0.3

External References