CVE-2024-50337

medium

Description

Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to any URL on server's behalf, which results in unauthenticated blind SSRF. This issue has been patched in version 1.11.28.

References

https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-rp2w-g734-jf8h

https://github.com/chamilo/chamilo-lms/releases/tag/v1.11.28

https://github.com/chamilo/chamilo-lms/commit/43a9bd1fb8b3f57e7935a6a6bc48975e2063b01b

Details

Source: Mitre, NVD

Published: 2026-03-02

Updated: 2026-03-03

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.00028