CVE-2026-33714 | Chamilo LMS up to 1.x AJAX Endpoint statistics.ajax.php Security::remove_XSS date_start/date_end sql injection (GHSA-w8c4-c7r8-qgw2)
A vulnerability categorized as critical has been discovered in Chamilo LMS up to 1.x. Impacted is the function Security::remove_XSS of the file public/main/inc/ajax/statistics.ajax.php of the component AJAX Endpoint. The manipulation of the argument date_start/date_end results in sql injection.
This vulnerability is reported as CVE-2026-33714. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.