Missing Authorization in Chamilo LMS - CVE-2026-61530
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to modify assignment submission feedback and grading data across course or session boundaries.
The vulnerability exists due to missing authorization in the POST /api/c_student_publication_comments/upload endpoint when handling attacker-controlled submission identifiers. A remote user can send a specially crafted request with an arbitrary submissionId to modify assignment submission feedback and grading data across course or session boundaries.
The issue also allows modification of qualification, qualificator_id, and date_of_qualification fields on the targeted submission.