Chamilo LMS
cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*
- < 1.11.34
A user enumeration vulnerability has been identified in Chamilo LMS versions prior to 1.11.34. This issue allows an attacker to determine the validity of usernames based on the application's response, creating a potential vector for further attacks such as password guessing or phishing.
Exploitation of this vulnerability allows for user enumeration, where an attacker can differentiate between valid and invalid usernames based on the application's response.
Users can upgrade to Chamilo LMS version 1.11.36 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.