CVE-2026-33705 | Chamilo LMS up to 1.11.37 AJAX Endpoint /main/template/default/ file information disclosure (GHSA-5wjg-8x28-px57)
A vulnerability, which was classified as problematic, has been found in Chamilo LMS up to 1.11.37. This vulnerability affects unknown code of the file /main/template/default/ of the component AJAX Endpoint. Performing a manipulation results in file and directory information exposure.
This vulnerability is identified as CVE-2026-33705. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.