关键漏洞信息: Title: Chamilo LMS <= v2.0.0 Beta 1 SocialController IDOR - Legal Consent Data Manipulation Description: - Multiple endpoints in Chamilo LMS 2.x are vulnerable to Insecure Direct Object Reference (IDOR) attacks. - An authenticated attacker can manipulate the parameter in POST requests to perform unauthorized operations on other users' legal consent and privacy-related data. Source: - https://note-hxlab.wetoland.com/share/w92t1Q0a74Gj Submitter: - User: angelkate (UID 94159) - Submission Date: 01/05/2026 08:14 AM (15 days ago) - Moderation Date: 01/17/2026 09:37 AM (12 days later) Status: Accepted VulDB Entry: 341698 Vulnerability Details: Chamilo LMS up to 2.0.0 Beta 1 Legal Consent SocialController.php deleteLegal userId improper authorization Points: 20