Описание
A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling malicious content injection, job manipulation, or email interception.
EPSS
Процентиль: 2%
0.00122
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-798
Связанные уязвимости
CVSS3: 5.4
github
13 дней назад
A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling malicious content injection, job manipulation, or email interception.
EPSS
Процентиль: 2%
0.00122
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-798