Chamilo LMS is a learning management system. Prior to 1.11.38, the get_user_info_from_username REST API endpoint returns personal information (email, first name, last name, user ID, active status) of any user to any authenticated user, including students. There is no authorization check. This vulnerability is fixed in 1.11.38.
References
Configurations
History
16 Apr 2026, 18:25
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/chamilo/chamilo-lms/commit/4a119f93abbfba6fe833580f2463c8d4afa500c2 - Patch | |
| References | () https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-qwch-82q9-q999 - Vendor Advisory | |
| First Time |
Chamilo chamilo Lms
Chamilo |
|
| CPE | cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:* |
10 Apr 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-10 19:16
Updated : 2026-04-16 18:25
NVD link : CVE-2026-33708
Mitre link : CVE-2026-33708
CVE.ORG link : CVE-2026-33708
JSON object : View
Products Affected
chamilo
- chamilo_lms
CWE
CWE-862
Missing Authorization
