CVE-2026-32893 | Chamilo LMS up to 2.0.0-RC.2 array_merge cross site scripting (GHSA-37jh-g64j-88mc)
A vulnerability labeled as problematic has been found in Chamilo LMS up to 2.0.0-RC.2. The affected element is the function array_merge. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-32893. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.