Chamilo LMS Redirect Vulnerability in Login Page

Vulnerability

A vulnerability in Chamilo LMS versions 1.11.0 prior to 2.0-beta.1 allows for malicious redirects through the 'redirect' parameter on the login page. This issue has been addressed in version 2.0-beta.2.

Impact

Exploitation of this vulnerability allows for open redirect attacks, where users can be sent to unintended destinations, potentially leading to phishing or other malicious activities.

Remediation

Users can update to Chamilo LMS version 2.0-beta.2 to address this vulnerability. Additionally, the commit '73ae629' can be applied as a patch.

Added: Apr 10, 2026, 7:08 PM
Updated: Apr 10, 2026, 7:08 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.2
exploitability
9.0
remediation
7.7
relevance
5.7
threat
3.2
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.