CVE-2026-32932: Chamilo LMS has an Open Redirect via Unvalidated 'page' Parameter in Session Course Edit
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Open Redirect vulnerability in the session course edit page allows an attacker to redirect an authenticated administrator to an arbitrary external URL after saving coach assignment changes. The redirect also leaks the idsession parameter to the attacker's server. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32932?
CVE-2026-32932 has a moderate severity level due to its potential to allow open redirects.
How do I fix CVE-2026-32932?
To fix CVE-2026-32932, upgrade Chamilo LMS to version 1.11.38 or 2.0.0-RC.3 or later.
Who is affected by CVE-2026-32932?
CVE-2026-32932 affects authenticated administrators using versions of Chamilo LMS prior to 1.11.38 and 2.0.0-RC.3.
What type of vulnerability is CVE-2026-32932?
CVE-2026-32932 is classified as an Open Redirect vulnerability.
Where can I find more details about CVE-2026-32932?
For more details, refer to the Chamilo LMS security advisories regarding CVE-2026-32932.