CVE-2026-32894
HIGHChamilo LMS Gradebook Results - Insecure Direct Object Reference
Title source: manualDescription
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebook result view page allows any authenticated teacher to delete any student's grade result across the entire platform by manipulating the delete_mark or resultdelete GET parameters. No ownership or course-scope verification is performed. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-rqpg-p95v-fv98
X_Refsource_Misc x_refsource_misc
https://github.com/chamilo/chamilo-lms/commit/3b03306d1a0301a81b9284e86893b27f518ab151
X_Refsource_Misc x_refsource_misc
https://github.com/chamilo/chamilo-lms/commit/740f5a6e192a52a3adde3c3241c86401b1d2c519
Scores
CVSS v3
7.1
EPSS
0.0028
EPSS Percentile
19.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-476
CWE-639
Status
published
Products (4)
chamilo/chamilo-lms
< 1.11.38
chamilo/chamilo-lms
>= 2.0.0-alpha.1, < 2.0.0-RC.3
chamilo/chamilo_lms
2.0.0 alpha1 (10 CPE variants)
chamilo/chamilo_lms
< 1.11.38
Published
Apr 10, 2026
Tracked Since
Apr 10, 2026