Junglewise Threat Intelligence

CVE-2026-32932: Chamilo LMS open redirect in session course edit page

CVE-2026-32932 · Severity: medium · CVSS 4.7 · Published 2026-04-10

Technologies: Chamilo Lms. Vendors: Chamilo.

Executive brief

Chamilo LMS, a popular open-source learning management system, contains a security flaw that allows attackers to redirect administrators to malicious websites. By tricking an administrator into clicking a specially crafted link, an attacker can send them to a phishing site after they perform routine course edits. This attack also leaks internal session identifiers, which could be used to further compromise the system or harvest credentials.

Technical details

An open redirect vulnerability exists in 'session_course_edit.php' due to insufficient validation of the 'page' GET parameter. While the application uses 'Security::remove_XSS()', this function only strips HTML tags and does not verify if the destination URL is local or trusted. An attacker can craft a URL that, upon an administrator saving coach assignment changes, triggers a 'Location' header redirect to an external domain. This redirect also appends the 'id_session' parameter to the malicious URL, leaking it to the attacker's server. The issue is fixed in versions 1.11.38 and 2.0.0-RC.3 by implementing an allowlist for the 'page' parameter.

Affected products

  • Chamilo Chamilo LMS < 1.11.38, < 2.0.0-RC.3

Timeline

  • 2026-04-10: advisory: Vendor advisory published via GitHub
  • 2026-04-10: disclosed: CVE-2026-32932 published
  • 2026-04-10: patched: Fixes released in 1.11.38 and 2.0.0-RC.3

References