Chamilo LMS is a learning management system. Prior to 1.11.38, the get_user_info_from_username REST API endpoint returns personal information (email, first name, last name, user ID, active status) of any user to any authenticated user, including students. There is no authorization check. This vulnerability is fixed in 1.11.38.
References
Configurations
History
No history.
Information
Published : 2026-04-10 19:16
Updated : 2026-06-17 10:37
NVD link : CVE-2026-33708
Mitre link : CVE-2026-33708
CVE.ORG link : CVE-2026-33708
JSON object : View
Products Affected
chamilo
- chamilo_lms
CWE
CWE-862
Missing Authorization
