CVE-2026-33707 | Chamilo LMS up to 1.11.37/2.0.0-RC.2 Password Reset email password recovery (GHSA-f27g-66gq-g7v2)
A vulnerability was found in Chamilo LMS up to 1.11.37/2.0.0-RC.2. It has been declared as problematic. Impacted is an unknown function of the component Password Reset Handler. The manipulation of the argument email results in weak password recovery.
This vulnerability is reported as CVE-2026-33707. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.