Executive brief
Chamilo LMS, a platform used for online learning and course management, contains a security flaw that allows anyone to view internal configuration files without logging in. These files reveal the inner workings of the system, including administrative web addresses and the structure of the management panel. An attacker can use this information to better understand the system's defenses and plan more sophisticated attacks against the organization's data or users.
Technical details
A sensitive information disclosure vulnerability exists in Chamilo LMS due to improper access controls on Twig template files (.tpl). The Apache configuration fails to restrict direct HTTP GET requests to the /main/template/default/ directory, allowing unauthenticated remote attackers to download template source files. These files contain sensitive metadata including AJAX endpoint URLs, internal variable names, permission check logic (e.g., admin checks), and the structural layout of the administrative panel. This exposure significantly aids an attacker in reconnaissance and the development of further exploits such as parameter tampering or authorization bypasses. The issue is resolved in version 1.11.38 by implementing access restrictions on these file types.
Affected products
- Chamilo Chamilo LMS < 1.11.38
Timeline
- 2026-04-10: disclosed
- 2026-04-10: advisory
- 2026-04-10: patched