CVE-2024-30619
Chamilo
CVE-2024-30619 affects Chamilo LMS, allowing unauthorized access to sensitive information. This Incorrect Access Control vulnerability permits non-authenticated attackers to retrieve the number of messages and online users. Specifically, requests to "/main/inc/ajax/message.ajax.php?a=get_count_message" and "/main/inc/ajax/online.ajax.php?a=get_users_online" expose this data without authentication. While the CVSS score is 7.5, the SOCRadar Vulnerability Risk Score (SVRS) is 30, indicating a lower immediate risk than other vulnerabilities, but the In The Wild tag suggests active exploitation. This information leak can be used for reconnaissance, potentially leading to further attacks. Organizations using Chamilo LMS should investigate and apply appropriate security measures. Although the SVRS indicates it's not a critical vulnerability, the possibility of exploitation makes it a threat that should not be ignored.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.