Description
Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download documents belonging to another student if they know the document's ID.
Remediation
References
Related Vulnerabilities
WordPress Plugin Battle Suit for Divi Security Bypass (1.10.1)
WordPress Plugin Advanced Custom Fields (ACF) 'acf_abspath' Parameter Remote File Include (3.5.1)
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-8707)
Oracle Database Server CVE-2012-0528 Vulnerability (CVE-2012-0528)