ZeroHour

CVE-2025-69581

PoC
CVSS 3.1
5.5 medium
EPSS
<1%p15
Published
()
Modified
Description

An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user information even after logout because proper cache-control is missing. Using the browser back button restores all personal data, allowing unauthorized users on the same device to view confidential information. This leads to profiling, impersonation, targeted attacks, and significant privacy risks.

Vendors
chamilo
Products
chamilo lms
Weakness
CWE-524
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.