CVE-2026-33705

Chamilo LMS is a learning management system. Prior to 1.11.38, Twig template files (.tpl) under /main/template/default/ are directly accessible without authentication via HTTP GET requests. These templates expose internal application logic, variable names, AJAX endpoint URLs, and admin panel structure. This vulnerability is fixed in 1.11.38.
Configurations

Configuration 1 (hide)

cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-10 19:16

Updated : 2026-06-17 10:37


NVD link : CVE-2026-33705

Mitre link : CVE-2026-33705

CVE.ORG link : CVE-2026-33705


JSON object : View

Products Affected

chamilo

  • chamilo_lms
CWE
CWE-538

Insertion of Sensitive Information into Externally-Accessible File or Directory