CVE-2026-33704 | Chamilo LMS up to 1.11.37 BigUpload Endpoint unrestricted upload (GHSA-phfx-pwwg-945v)
A vulnerability has been found in Chamilo LMS up to 1.11.37 and classified as critical. This affects an unknown part of the component BigUpload Endpoint. Performing a manipulation results in unrestricted upload.
This vulnerability is cataloged as CVE-2026-33704. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.