CVE-2025-69581 Details
Description
An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user information even after logout because proper cache-control is missing. Using the browser back button restores all personal data, allowing unauthorized users on the same device to view confidential information. This leads to profiling, impersonation, targeted attacks, and significant privacy risks.
A vulnerability in Chamillo LMS version 1.11.2 allows unauthorized access to sensitive user information through the Social Network /personal_data endpoint. The issue arises from inadequate cache-control, which enables the retrieval of personal data even after a user has logged out. This flaw can be exploited by unauthorized users on the same device, leading to potential profiling, impersonation, targeted attacks, and significant privacy risks.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/chamilo/chamilo-lms | [email protected] | Product |
| https://github.com/Rivek619/CVE-2025-69581 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-524 | Use of Cache Containing Sensitive Information | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| chamilo chamilo lms | 1.11.2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 5, 2026 | Initial Analysis | [email protected] |
| Jan 20, 2026 | CVE Modified | CISA-ADP |
| Jan 16, 2026 | CVE Modified | CISA-ADP |
| Jan 16, 2026 | New CVE Received | [email protected] |