Junglewise Threat Intelligence

CVE-2026-33703: Chamilo LMS IDOR in social-network personal-data endpoint

CVE-2026-33703 · Severity: medium · CVSS 6.5 · Published 2026-04-10

Technologies: Chamilo Lms. Vendors: Chamilo.

Executive brief

Chamilo LMS, a popular open-source learning management system, contains a security flaw that allows any logged-in user to view the private information of any other user on the platform. By simply changing a user ID in a web request, an attacker can access sensitive details including full names, contact information, and security tokens. This could lead to a total data breach of the platform, exposing both student and administrator credentials.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the `/social-network/personal-data/{userId}` endpoint of Chamilo LMS. The `SocialController` implements a class-level role check (`ROLE_USER`) but fails to perform object-level authorization to ensure the requester owns the data or has administrative privileges. An authenticated attacker can supply an arbitrary `userId` to the `getPersonalData` method, which then serializes and returns sensitive information including email, physical address, and the `ApiToken`. This vulnerability is fixed in version 2.0.0-RC.3.

Affected products

  • Chamilo Chamilo LMS > 1.11.*, <= 2.0-RC.2

Timeline

  • 2026-04-10: advisory: Original advisory published by GitHub and Chamilo.
  • 2026-04-10: disclosed
  • 2026-04-10: patched: Fixed in version 2.0.0-RC.3.

References