CVE-2026-32930: Chamilo LMS has an IDOR in Gradebook Allows Cross-Course Evaluation Edit Without Ownership Check
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebook evaluation edit page allows any authenticated teacher to view and modify the settings (name, max score, weight) of evaluations belonging to any other course by manipulating the editeval GET parameter. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32930?
The severity of CVE-2026-32930 is classified as medium due to its potential to allow unauthorized edits of evaluations.
How do I fix CVE-2026-32930?
To fix CVE-2026-32930, update Chamilo LMS to version 1.11.38 or 2.0.0-RC.3 or later.
What is the impact of CVE-2026-32930?
CVE-2026-32930 allows authenticated users to edit gradebook evaluations across courses without proper ownership checks.
Who is affected by CVE-2026-32930?
Users of Chamilo LMS versions prior to 1.11.38 and 2.0.0-RC.3 are affected by CVE-2026-32930.
What type of vulnerability is CVE-2026-32930?
CVE-2026-32930 is an Insecure Direct Object Reference (IDOR) vulnerability.