Vulnerability Description
Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the REST API stats endpoint allows any authenticated user (including low-privilege students with ROLE_USER) to read any other user's learning progress, certificates, and gradebook scores for any course, without enrollment or supervisory relationship. This vulnerability is fixed in 2.0.0-RC.3.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chamilo | Chamilo Lms | <= 1.11.38 |
Related Weaknesses (CWE)
References
- https://github.com/chamilo/chamilo-lms/commit/792ba05953470ca971617fe2674ed14c14Patch
- https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-j2pr-2r5w-jrpjVendor Advisory
FAQ
What is CVE-2026-33141?
CVE-2026-33141 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the REST API stats endpoint allows any authenticated user (including low-p...
How severe is CVE-2026-33141?
CVE-2026-33141 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-33141?
Check the references section above for vendor advisories and patch information. Affected products include: Chamilo Chamilo Lms.