
CVE-2026-31940 Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.php, user-controlled request parameters are directly used to set th… https://www.cve.org/CVERecord?id=CVE-2026-31940
Post summary
The CVE-2026-31940 vulnerability in Chamilo LMS involves unvalidated request parameters in main/lp/aicc_hacp.php, affecting versions before 1.11.38/2.0.0-RC.3; newer releases contain the patch.
