← Back

CVE-2026-33710

nvd nist
Published: Apr 10, 2026Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: security-advisories@github.com (Secondary)

Description

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, REST API keys are generated using md5(time() + (user_id * 5) - rand(10000, 10000)). The rand(10000, 10000) call always returns exactly 10000 (min == max), making the formula effectively md5(timestamp + user_id*5 - 10000). An attacker who knows a username and approximate key creation time can brute-force the API key. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.

Affected (11)

Products: Chamilo: Chamilo Lms
1 product
Chamilo Lms
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Chamilo
Before 1.11.38
Version 2.0.0 alpha1
Version 2.0.0 alpha2
Version 2.0.0 alpha3
Version 2.0.0 alpha4
Version 2.0.0 alpha5
Version 2.0.0 beta1
Version 2.0.0 beta2
Version 2.0.0 beta3
Version 2.0.0 rc1
Version 2.0.0 rc2

Timeline

No history available yet.