Описание
An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without any authorization or authentication checks, bypassing the expected admin-only deletion restriction.
Ссылки
- ExploitThird Party Advisory
- Product
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:classroomio:classroomio:0.1.13:*:*:*:*:*:*:*
EPSS
Процентиль: 39%
0.00472
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-862
Связанные уязвимости
CVSS3: 9.1
github
9 месяцев назад
An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without any authorization or authentication checks, bypassing the expected admin-only deletion restriction.
EPSS
Процентиль: 39%
0.00472
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-862