Incorrect authorization in Chamilo LMS - CVE-2026-54748
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to modify course tool-introduction content and execute arbitrary script in other users' browsers.
The vulnerability exists due to improper authorization in the ResourceVoter for AbstractResource-gated entities when handling API Platform endpoints and legacy access checks. A remote user can access and modify CToolIntro objects outside their authorized scope to modify course tool-introduction content and execute arbitrary script in other users' browsers.
The issue can affect resources protected only by this voter, and exploitation can cross tenant and course boundaries.