CVE-2025-69581: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2025-69581 is an information disclosure vulnerability in Chamilo LMS version 1.11.2 caused by missing cache-control headers on the Social Network /personal_data endpoint. After a user logs out, sensitive personally identifiable information (PII) remains accessible in the browser cache, allowing any subsequent user of the same device to retrieve it via the browser's back button. The vulnerability was discovered by Rivek Raj Tamang (RivuDon) from Sikkim, India, and was published on January 16, 2026 (GitHub PoC). It carries a CVSS v3.1 base score of 5.5 (Medium), assessed with a local attack vector requiring user interaction (Feedly).

Technical details

The root cause is classified under CWE-524 (Use of Cache Containing Sensitive Information), where the /personal_data endpoint in Chamilo LMS's Social Network module fails to set appropriate HTTP cache-control headers (e.g., Cache-Control: no-store, no-cache) (GitHub PoC). Because the browser caches the full response containing user PII, the data persists in the browser's history even after session termination. Exploitation requires physical or logical access to the same device and browser session used by the victim, and is triggered simply by pressing the browser's back button after logout — no technical skill or special tooling is required.

Impact

Successful exploitation exposes full sensitive user PII — including personal profile data — to any unauthorized individual with access to the same device and browser. This can enable user profiling, impersonation, and targeted social engineering or phishing attacks against the affected users. The impact is limited to confidentiality (no integrity or availability impact), and is most significant in shared-device environments such as libraries, computer labs, or kiosks commonly found in educational institutions that use Chamilo LMS (Feedly, GitHub PoC).

Exploitability

A public proof-of-concept repository exists on GitHub, published by the discoverer (GitHub PoC). There is no evidence of active in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.031% (0.000310), indicating a very low probability of exploitation in the near term (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Identify target: Locate a shared device (e.g., library computer, lab workstation) where a user has previously logged into a Chamilo LMS 1.11.2 instance.
  2. Wait for logout: The legitimate user navigates to Social Network > Personal Data (the /personal_data endpoint), views their PII, and then logs out of the application.
  3. Access cached data: On the same browser, press the browser's back button immediately after logout.
  4. Retrieve PII: The browser renders the previously cached /personal_data page, displaying the victim's full sensitive personal information without any reauthentication, due to the absence of Cache-Control: no-store or equivalent headers.
  5. Exploit data: Use the exposed PII for profiling, impersonation, or targeted attacks against the victim (GitHub PoC).

Indicators of compromise

  • Logs: Web server access logs showing requests to the /personal_data endpoint from the same IP or session immediately following a logout event (e.g., a GET request to /personal_data with no valid session cookie).
  • Network: Absence of Cache-Control: no-store or Pragma: no-cache headers in HTTP responses from the /personal_data endpoint, detectable via proxy or network inspection tools.
  • Browser: Browser history or cache entries for the /personal_data URL persisting after logout on shared devices.

Mitigation and workarounds

No official vendor patch has been confirmed for Chamilo LMS 1.11.2 at the time of disclosure (Feedly). As an immediate workaround, administrators should configure the web server or application to send strict cache-control headers on all sensitive endpoints, particularly /personal_data: Cache-Control: no-store, no-cache, must-revalidate, max-age=0 and Pragma: no-cache. Additionally, organizations should enforce policies against using Chamilo on shared devices, and consider implementing logout mechanisms that programmatically clear browser cache. Users should be advised to use private/incognito browsing sessions on shared devices.

Community reactions

The vulnerability received brief coverage on social media platforms including Mastodon and Bluesky via TheHackerWire, and was noted in cybersecurity aggregator blogs (Feedly). No significant vendor statement from Chamilo or notable expert commentary beyond the discoverer's disclosure has been identified.

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management