LDAP injection in Chamilo LMS - CVE-2026-61585
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to LDAP injection in LDAP-integration code paths when building LDAP search filters from user-controlled values. A remote attacker can supply crafted input in parameters such as annee, login/username, or keyword_* to disclose sensitive information.
Exploitation is possible only in deployments with LDAP authentication or LDAP user import enabled.