Executive brief
Chamilo LMS, a widely used learning management system, contains a critical flaw in its password recovery system. An attacker who knows a user's email address can mathematically predict their password reset link and take over their account without any interaction from the victim. This could lead to unauthorized access to student data, course materials, and administrative controls.
Technical details
A vulnerability in the default password reset mechanism of Chamilo LMS (located in login.lib.php) stems from the use of a deterministic token generation algorithm. The system generates reset tokens by simply calculating the SHA-1 hash of the user's email address without incorporating any random salts, expiration timestamps, or rate limiting. Because the token is static and predictable, an attacker can compute the 'secret' word for any known email address and submit a password reset request directly. This is further exacerbated by the use of sequential user IDs and the lack of a requirement for a reset to be initiated by the legitimate user. The issue is resolved in versions 1.11.38 and 2.0.0-RC.3.
Affected products
- Chamilo Chamilo LMS < 1.11.38, < 2.0.0-RC.3
Timeline
- 2026-04-10: disclosed
- 2026-04-10: advisory
- 2026-04-10: patched