Authorization bypass through user-controlled key in Chamilo LMS - CVE-2026-61623
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to authorization bypass through a user-controlled key in public/main/my_space/myStudents.php when handling a user-supplied student parameter. A remote user can supply an arbitrary student parameter to disclose sensitive information.
The issue exposes quiz scores, learning progress, time-on-task, last login, and personal details for students not enrolled in any course taught by the requesting teacher.