CVE-2026-34160
chamilo chamilo-lms, chamilo lms
Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the PENS (Package Exchange Notification Services) plugin endpoint at public/plugin/Pens/pens.php is accessible without authentication and accepts a user-controlled package-url parameter that the server fetches using curl without filtering private or internal IP addresses, enabling unauthenticated Server-Side Request Forgery (SSRF). An attacker can exploit this to probe internal network services, access cloud metadata endpoints (such as 169.254.169.254) to steal IAM credentials and sensitive instance m...
- CVSS
- 8.6
- EPSS
- 0.34% 27.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.15