Логотип exploitDog
bind:CVE-2023-3345
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-3345

Количество 2

Количество 2

nvd логотип

CVE-2023-3345

больше 2 лет назад

The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-2xrx-pwqh-wmrm

больше 2 лет назад

The LMS by Masteriyo WordPress plugin before 1.6.8 does not properly safeguards sensitive user information, like other user's email addresses, making it possible for any students to leak them via some of the plugin's REST API endpoints.

CVSS3: 6.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-3345

The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students

CVSS3: 6.5
65%
Средний
больше 2 лет назад
github логотип
GHSA-2xrx-pwqh-wmrm

The LMS by Masteriyo WordPress plugin before 1.6.8 does not properly safeguards sensitive user information, like other user's email addresses, making it possible for any students to leak them via some of the plugin's REST API endpoints.

CVSS3: 6.5
65%
Средний
больше 2 лет назад

Уязвимостей на страницу