


Perceptive Security
SOC/SIEM Consultancy

An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user information even after logout because pro…
Published:
15 januari 2026 om 23:00:00
Alert date:
16 januari 2026 om 23:00:55
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A security vulnerability was discovered in Chamilo LMS version 1.11.2 affecting the Social Network /personal_data endpoint. The vulnerability stems from missing proper cache-control headers, which allows sensitive user information to remain accessible even after logout. Unauthorized users can exploit this by using the browser's back button to view confidential personal data of previously logged-in users on the same device. This creates significant privacy risks including potential for profiling, impersonation, and targeted attacks against users. The vulnerability affects user data confidentiality and could lead to serious privacy breaches in educational environments using the Chamilo LMS platform.
Technical details
Mitigation steps:
Affected products:
Chamilo LMS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-69581
https://github.com/Rivek619/CVE-2025-69581
https://github.com/chamilo/chamilo-lms
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
