Cross-site request forgery in Chamilo LMS - CVE-2026-61656
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to manipulate student grades and evaluation data.
The vulnerability exists due to cross-site request forgery in the Gradebook module endpoints responsible for managing evaluations and grades when handling crafted GET requests without proper anti-CSRF token validation. A remote attacker can trick a victim into visiting a maliciously crafted webpage to manipulate student grades and evaluation data.
User interaction is required, and exploitation targets authenticated administrator, teacher, or course coach sessions.