Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download documents belonging to another student if they know the document's ID.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.