Impact
Chamilo LMS before version 2.0.0‑RC.3 has an insecure direct object reference error in the /social‑network/personal‑data/{userId} endpoint. Any user who has logged in can modify the userId parameter and retrieve the complete personal profile and API tokens of any other user. This flaw leads to a full data breach, exposing private information and authentication credentials.
Affected Systems
Versions of Chamilo LMS released by the Chamilo vendor that are older than 2.0.0‑RC.3 are affected. The vulnerability is located in the web application’s social‑network personal‑data endpoint.
Risk and Exploitability
The CVSS base score of 7.1 places this vulnerability in the high‑severity range. Although EPSS information is not available, the requirement that the attacker only needs valid credentials and a simple HTTP request increases the likelihood of exploitation. The flaw is not listed in the CISA KEV catalog, but the potential for mass data leakage requires immediate action.
OpenCVE Enrichment