Skip to content
CVE-2026-33707 TheHackerWire / 18h Attack Vector How the vulnerability can be exploited Network Scope Impact beyond vulnerable component Unchanged

CVE-2026-33707 TheHackerWire / 18h Attack Vector How the vulnerability can be exploited Network Scope Impact beyond vulnerable component Unchanged

www.thehackerwire.com April 11, 2026

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random component, no expiration, and no rate limiting. An attacker who knows a user's email can compute the reset token and change the victim's password without authentication. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.

Modify values to recalculate the CVSS score in real-time

0.07% probability of exploitation in the 30 days.

Higher than 20% of all CVEs

Stay informed the most severe security threats discovered this week

Extracted Entities

Platforms (1)