top of page
perceptive_background_267k.jpg

An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user information even after logout because pro…

Published:

15 januari 2026 om 23:00:00

Alert date:

16 januari 2026 om 23:00:55

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

A security vulnerability was discovered in Chamilo LMS version 1.11.2 affecting the Social Network /personal_data endpoint. The vulnerability stems from missing proper cache-control headers, which allows sensitive user information to remain accessible even after logout. Unauthorized users can exploit this by using the browser's back button to view confidential personal data of previously logged-in users on the same device. This creates significant privacy risks including potential for profiling, impersonation, and targeted attacks against users. The vulnerability affects user data confidentiality and could lead to serious privacy breaches in educational environments using the Chamilo LMS platform.

Technical details

Mitigation steps:

Affected products:

Chamilo LMS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page