Impact
An insecure direct object reference in the REST API stats endpoint permits any authenticated user, regardless of role, to retrieve another user's learning progress, certificates, and gradebook scores for any course. This unauthorized disclosure breaches confidentiality and exposes sensitive educational records, while the lack of enrollment or supervisory checks creates a wide attack surface.
Affected Systems
Chamilo Learning Management System installations running versions prior to 2.0.0‑RC.3 are affected. The vulnerability applies across all deployments where the REST API stats endpoint is accessed by authenticated users, including community‑edited configurations.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, and the absence of an EPSS score suggests that there is no current public exploitation data. It is not listed in the CISA KEV catalog. Extrapolating from the description, an attacker only needs valid credentials and the ability to issue API requests; therefore the vulnerability is exploitable in any environment where authenticated users can reach the endpoint.
OpenCVE Enrichment