CVE-2026-33737
MEDIUMChamilo LMS XML Parsing - XML External Entity Injection
Title source: manualDescription
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use simplexml_load_string() without XXE protection. With LIBXML_NOENT flag, arbitrary server files can be read. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-c4ww-qgf2-v89j
X_Refsource_Misc x_refsource_misc
https://github.com/chamilo/chamilo-lms/commit/22b1cb1c609b643765c88654155aba27070c927e
X_Refsource_Misc x_refsource_misc
https://github.com/chamilo/chamilo-lms/commit/af6b7002af7c15825e98fc522e2ead0d00cacaa3
Scores
CVSS v3
5.3
EPSS
0.0022
EPSS Percentile
12.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-611
Status
published
Products (4)
chamilo/chamilo-lms
< 1.11.38
chamilo/chamilo-lms
>= 2.0.0-alpha.1, < 2.0.0-RC.3
chamilo/chamilo_lms
2.0.0 alpha1 (10 CPE variants)
chamilo/chamilo_lms
< 1.11.38
Published
Apr 10, 2026
Tracked Since
Apr 11, 2026