
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69581 is an information disclosure vulnerability in Chamilo LMS version 1.11.2 caused by missing cache-control headers on the Social Network /personal_data endpoint. After a user logs out, sensitive personally identifiable information (PII) remains accessible in the browser cache, allowing any subsequent user of the same device to retrieve it via the browser's back button. The vulnerability was discovered by Rivek Raj Tamang (RivuDon) from Sikkim, India, and was published on January 16, 2026 (GitHub PoC). It carries a CVSS v3.1 base score of 5.5 (Medium), assessed with a local attack vector requiring user interaction (Feedly).
The root cause is classified under CWE-524 (Use of Cache Containing Sensitive Information), where the /personal_data endpoint in Chamilo LMS's Social Network module fails to set appropriate HTTP cache-control headers (e.g., Cache-Control: no-store, no-cache) (GitHub PoC). Because the browser caches the full response containing user PII, the data persists in the browser's history even after session termination. Exploitation requires physical or logical access to the same device and browser session used by the victim, and is triggered simply by pressing the browser's back button after logout — no technical skill or special tooling is required.
Successful exploitation exposes full sensitive user PII — including personal profile data — to any unauthorized individual with access to the same device and browser. This can enable user profiling, impersonation, and targeted social engineering or phishing attacks against the affected users. The impact is limited to confidentiality (no integrity or availability impact), and is most significant in shared-device environments such as libraries, computer labs, or kiosks commonly found in educational institutions that use Chamilo LMS (Feedly, GitHub PoC).
A public proof-of-concept repository exists on GitHub, published by the discoverer (GitHub PoC). There is no evidence of active in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.031% (0.000310), indicating a very low probability of exploitation in the near term (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
/personal_data endpoint), views their PII, and then logs out of the application./personal_data page, displaying the victim's full sensitive personal information without any reauthentication, due to the absence of Cache-Control: no-store or equivalent headers./personal_data endpoint from the same IP or session immediately following a logout event (e.g., a GET request to /personal_data with no valid session cookie).Cache-Control: no-store or Pragma: no-cache headers in HTTP responses from the /personal_data endpoint, detectable via proxy or network inspection tools./personal_data URL persisting after logout on shared devices.No official vendor patch has been confirmed for Chamilo LMS 1.11.2 at the time of disclosure (Feedly). As an immediate workaround, administrators should configure the web server or application to send strict cache-control headers on all sensitive endpoints, particularly /personal_data: Cache-Control: no-store, no-cache, must-revalidate, max-age=0 and Pragma: no-cache. Additionally, organizations should enforce policies against using Chamilo on shared devices, and consider implementing logout mechanisms that programmatically clear browser cache. Users should be advised to use private/incognito browsing sessions on shared devices.
The vulnerability received brief coverage on social media platforms including Mastodon and Bluesky via TheHackerWire, and was noted in cybersecurity aggregator blogs (Feedly). No significant vendor statement from Chamilo or notable expert commentary beyond the discoverer's disclosure has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."