Описание
The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.5.0 (исключая)
cpe:2.3:a:automattic:sensei_lms:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 97%
0.33749
Средний
5.3 Medium
CVSS3
Дефекты
CWE-639
Связанные уязвимости
CVSS3: 5.3
github
больше 3 лет назад
The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers
EPSS
Процентиль: 97%
0.33749
Средний
5.3 Medium
CVSS3
Дефекты
CWE-639