CVE-2026-32932 | Chamilo LMS up to 1.11.37/2.0.0-RC.2 External URL id_session redirect
A vulnerability classified as problematic was found in Chamilo LMS up to 1.11.37/2.0.0-RC.2. The impacted element is an unknown function of the component External URL Handler. Executing a manipulation of the argument id_session can lead to open redirect.
This vulnerability is tracked as CVE-2026-32932. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.