Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random component, no expiration, and no rate limiting. An attacker who knows a user's email can compute the reset token and change the victim's password without authentication. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-04-10 19:16
Updated : 2026-06-17 10:37
NVD link : CVE-2026-33707
Mitre link : CVE-2026-33707
CVE.ORG link : CVE-2026-33707
JSON object : View
Products Affected
chamilo
- chamilo_lms
CWE
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
