CVE-2024-30619: High severity chamilo lms vulnerability
Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number of online users via "/main/inc/ajax/message.ajax.php?a=getcountmessage" AND "/main/inc/ajax/online.ajax.php?a=getusersonline."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30619?
CVE-2024-30619 is classified as a high-severity vulnerability due to incorrect access control allowing unauthenticated attackers to access sensitive information.
How do I fix CVE-2024-30619?
To fix CVE-2024-30619, upgrade Chamilo LMS to a patched version that addresses the incorrect access control issue.
What type of vulnerability is CVE-2024-30619?
CVE-2024-30619 is an Incorrect Access Control vulnerability affecting Chamilo LMS.
Who is affected by CVE-2024-30619?
Users of Chamilo LMS Version 1.11.26 are affected by CVE-2024-30619.
Can CVE-2024-30619 be exploited remotely?
Yes, CVE-2024-30619 can be exploited remotely by non-authenticated attackers.