CVE-2026-33141
MEDIUMChamilo LMS has an IDOR in REST API Stats Endpoint Exposes Any User's Learning Data
Title source: cnaDescription
Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the REST API stats endpoint allows any authenticated user (including low-privilege students with ROLE_USER) to read any other user's learning progress, certificates, and gradebook scores for any course, without enrollment or supervisory relationship. This vulnerability is fixed in 2.0.0-RC.3.
Scores
CVSS v3
6.5
EPSS
0.0002
EPSS Percentile
5.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-639
CWE-862
Status
published
Products (3)
chamilo/chamilo-lms
< 2.0.0-RC.3
chamilo/chamilo_lms
2.0.0 alpha1 (10 CPE variants)
chamilo/chamilo_lms
< 1.11.38
Published
Apr 10, 2026
Tracked Since
Apr 11, 2026