Description
Incorrect access control in Chamilo v1.11.x up to v1.11.18 allows a student to arbitrarily access and modify another student's personal notes.
Remediation
References
Related Vulnerabilities
WordPress Plugin Disqus Comment System Cross-Site Scripting (2.68)
WordPress Plugin Filter Custom Fields & Taxonomies Light Unspecified Vulnerability (1.04)
MySQL CVE-2023-22026 Vulnerability (CVE-2023-22026)
WordPress Plugin Scriptless Social Sharing Cross-Site Scripting (3.2.1)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-4303)