A vulnerability classified as critical has been found in Chamilo LMS up to 1.11.37/2.0.0-RC.2. Impacted is an unknown function of the file main/lp/aicc_hacp.php of the component Request Parameter Handler. This manipulation causes session fixation. Remote exploitation of the attack is possible.
| Vendor | Product | Versions |
|---|---|---|
| chamilo | chamilo-lms | < 1.11.38, >= 2.0.0-alpha.1, < 2.0.0-RC.3 |
Updated severity to CRITICAL, added new description details, marked as actively exploited, and provided the fixed version number 1.11.38.
Initial creation