cross-course blog api authorization bypass in chamilo
ghsa-438r-9jh4-mmfc let low-privileged chamilo lms users read, create, modify, and comment on blog resources outside their enrolled course scope
August 1, 2026 2 min read vulnerability cve web exploitation idor