Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download documents belonging to another student if they know the document's ID.
{ "versions": [ { "introduced": "1.11.0" }, { "last_affected": "1.11.18" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-34958.json"