OVERVIEW CVE-2026-33737 affects Chamilo LMS, a learning management system, in versions prior to 1.11.38 and 2.0.0-RC.3. The vulnerability stems from improper use of the simplexml_load_string() function without XXE (XML External Entity) protection. When the LIBXML_NOENT flag is enabled, attackers can exploit this flaw to read arbitrary files from the affected server. SEVERITY This vulnerability carries a CVSS 3.1 score of 6.5 (MEDIUM severity) with a network-based attack vector requiring low complexity and low privilege user credentials. The attack requires no user interaction and compromises confidentiality by allowing unauthorized file access, though integrity and availability remain unaffected. The FAUCET Risk Score of 35.0 indicates moderate organizational risk. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog, and community attention remains minimal as indicated by the inactive Hot List status. The extremely low EPSS score of 0.0003 suggests this vulnerability ranks well below average in terms of real-world exploitation probability compared to other disclosed CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.11.38CPE matchmatch criteria | cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha1:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha2:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha3:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha4:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.