Описание
Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new user then use the edit user function to change this new user to administrator privilege.
Ссылки
- PatchVendor Advisory
- ExploitThird Party Advisory
- PatchVendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:chamilo:chamilo_lms:1.11.10:*:*:*:*:*:*:*
EPSS
Процентиль: 41%
0.00189
Низкий
4.9 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-269
Связанные уязвимости
github
больше 3 лет назад
Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new user then use the edit user function to change this new user to administrator privilege.
EPSS
Процентиль: 41%
0.00189
Низкий
4.9 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-269