Executive brief
Chamilo LMS, a popular open-source learning management system, contains a security flaw where any logged-in user (including students) can access the private personal information of any other user. By querying a specific web interface, an attacker can retrieve full names, email addresses, and account statuses for the entire user directory. This data exposure can be used to facilitate targeted phishing attacks or to gain unauthorized access to administrative accounts.
Technical details
A missing authorization check (CWE-862) exists in the 'get_user_info_from_username' REST API endpoint located in 'main/webservices/api/v2.php'. The endpoint fails to verify if the requesting user has administrative privileges before returning sensitive data. An authenticated attacker, such as a student, can provide a username to the 'loginname' parameter to receive a JSON response containing the target's user ID, first name, last name, email address, and active status. This vulnerability can be leveraged for mass data harvesting or as a reconnaissance step in more complex attack chains involving password resets. The issue is resolved in version 1.11.38 by implementing an 'api_is_platform_admin()' check.
Affected products
- Chamilo Chamilo LMS < 1.11.38
Timeline
- 2026-04-10: advisory: Vendor advisory published via GitHub
- 2026-04-10: disclosed: CVE-2026-33708 published
- 2026-04-16: patched: NVD analysis updated with patch information