Open redirect in Chamilo LMS - CVE-2026-61602
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to redirect victims to attacker-controlled sites.
The vulnerability exists due to improper input validation in main/calendar/ical_export.php when handling error paths that issue redirects based on the HTTP_REFERER header. A remote user can supply a crafted referer value to redirect victims to attacker-controlled sites.
The issue is usable for phishing and redirect chaining.