CVE-2026-33708 | Chamilo LMS up to 1.11.37 REST API Endpoint get_user_info_from_username authorization (GHSA-qwch-82q9-q999)
A vulnerability has been found in Chamilo LMS up to 1.11.37 and classified as problematic. Impacted is the function get_user_info_from_username of the component REST API Endpoint. The manipulation leads to missing authorization.
This vulnerability is listed as CVE-2026-33708. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.