296,225
Total vulnerabilities in the database
Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download documents belonging to another student if they know the document's ID.
CVSS v3:
No CWE or OWASP classifications available.