Executive brief
Campus Educativa, an e-learning platform used by companies to manage and sell training courses, contains a security flaw that allows unauthorized access to student information. An attacker can exploit this to download spreadsheets containing sensitive personal details such as full names, email addresses, and phone numbers of all users enrolled in various courses. This could lead to large-scale data theft, privacy violations, and potential phishing campaigns targeting the platform's users.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the '/administracion/admin_usuarios.cgi' endpoint of Campus Educativa. The application fails to perform adequate authorization checks on the 'wid_cursoActual' parameter when the 'wAccion' parameter is set to 'listado_xlsx'. A remote, unauthenticated attacker can iterate through course IDs (brute-force) to trigger the export of Excel files containing usernames, names, emails, and phone numbers for all enrolled students. The vulnerability is fixed in version 14.05.00-159.
Affected products
- Educativa Campus Educativa 14.05.00-35 up to (but not including) 14.05.00-159
Timeline
- 2026-03-16: disclosed
- 2026-03-16: advisory
- 2026-03-16: patched: Fixed in version 14.05.00-159