Vulnerability Description
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebook evaluation edit page allows any authenticated teacher to view and modify the settings (name, max score, weight) of evaluations belonging to any other course by manipulating the editeval GET parameter. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chamilo | Chamilo Lms | < 1.11.38 |
Related Weaknesses (CWE)
References
- https://github.com/chamilo/chamilo-lms/commit/63e1e6d3d717bd537c7c61719416da35aaPatch
- https://github.com/chamilo/chamilo-lms/commit/f03f681df939db0429edc8414fb3ce4e4bPatch
- https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-9h22-wrg7-82q6Vendor Advisory
FAQ
What is CVE-2026-32930?
CVE-2026-32930 is a vulnerability with a CVSS score of 7.1 (HIGH). Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebook evaluation edit page allows any authenticated te...
How severe is CVE-2026-32930?
CVE-2026-32930 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-32930?
Check the references section above for vendor advisories and patch information. Affected products include: Chamilo Chamilo Lms.