Executive brief
Chamilo LMS, a popular open-source learning management system, contains a security flaw that allows any logged-in user to view the private information of any other user on the platform. By simply changing a user ID in a web request, an attacker can access sensitive details including full names, contact information, and security tokens. This could lead to a total data breach of the platform, exposing both student and administrator credentials.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the `/social-network/personal-data/{userId}` endpoint of Chamilo LMS. The `SocialController` implements a class-level role check (`ROLE_USER`) but fails to perform object-level authorization to ensure the requester owns the data or has administrative privileges. An authenticated attacker can supply an arbitrary `userId` to the `getPersonalData` method, which then serializes and returns sensitive information including email, physical address, and the `ApiToken`. This vulnerability is fixed in version 2.0.0-RC.3.
Affected products
- Chamilo Chamilo LMS > 1.11.*, <= 2.0-RC.2
Timeline
- 2026-04-10: advisory: Original advisory published by GitHub and Chamilo.
- 2026-04-10: disclosed
- 2026-04-10: patched: Fixed in version 2.0.0-RC.3.