← Back

CVE-2026-33707

nvd nist
Published: Apr 10, 2026Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random component, no expiration, and no rate limiting. An attacker who knows a user's email can compute the reset token and change the victim's password without authentication. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.

Affected (11)

Products: Chamilo: Chamilo Lms
1 product
Chamilo Lms
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Chamilo
Before 1.11.38
Version 2.0.0 alpha1
Version 2.0.0 alpha2
Version 2.0.0 alpha3
Version 2.0.0 alpha4
Version 2.0.0 alpha5
Version 2.0.0 beta1
Version 2.0.0 beta2
Version 2.0.0 beta3
Version 2.0.0 rc1
Version 2.0.0 rc2

Timeline

No history available yet.