CVE-2023-39582: Chamilo Lms

Medium severity, CVSS 4.9. EPSS: 0.7% chance of exploitation in the next 30 days.

SQL Injection vulnerability in Chamilo LMS v.1.11 thru v.1.11.20 allows a remote privileged attacker to obtain sensitive information via the import sessions functions.

Affected products

  • Chamilo Chamilo Lms: from 1.11, up to and including 1.11.20

Published 2023-09-01. Last modified 2026-06-17.