CVE-2026-31941 | Chamilo LMS up to 1.11.37/2.0.0-RC.2 Social Wall read_url_with_open_graph social_wall_new_msg_main server-side request forgery (GHSA-q74c-mx8x-489h)
A vulnerability was found in Chamilo LMS up to 1.11.37/2.0.0-RC.2. It has been classified as critical. Affected by this issue is the function read_url_with_open_graph of the component Social Wall. Performing a manipulation of the argument social_wall_new_msg_main results in server-side request forgery.
This vulnerability is reported as CVE-2026-31941. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.