CVE-2026-33708

Chamilo LMS is a learning management system. Prior to 1.11.38, the get_user_info_from_username REST API endpoint returns personal information (email, first name, last name, user ID, active status) of any user to any authenticated user, including students. There is no authorization check. This vulnerability is fixed in 1.11.38.
Configurations

Configuration 1 (hide)

cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:*

History

16 Apr 2026, 18:25

Type Values Removed Values Added
References () https://github.com/chamilo/chamilo-lms/commit/4a119f93abbfba6fe833580f2463c8d4afa500c2 - () https://github.com/chamilo/chamilo-lms/commit/4a119f93abbfba6fe833580f2463c8d4afa500c2 - Patch
References () https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-qwch-82q9-q999 - () https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-qwch-82q9-q999 - Vendor Advisory
First Time Chamilo chamilo Lms
Chamilo
CPE cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:*

10 Apr 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-10 19:16

Updated : 2026-04-16 18:25


NVD link : CVE-2026-33708

Mitre link : CVE-2026-33708

CVE.ORG link : CVE-2026-33708


JSON object : View

Products Affected

chamilo

  • chamilo_lms
CWE
CWE-862

Missing Authorization