Security Advisory
CVE-2023-34958
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download documents belonging to another student if they know the documents ID.