CVE-2023-3345
LMS by Masteriyo < 1.6.8 - Information Exposure
Record summary
CVE-2023-3345 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.
Description
The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 30, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
LMS by MasteriyoDefault status: unaffected | CVE List | Before 1.6.8 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMLMS by Masteriyo < 1.6.8 - Information ExposureCVSS 6.5
The plugin does not properly safeguards sensitive user information, like other user's email addresses, making it possible for any students to leak them via some of the plugin's REST API endpoints.
Impact
An attacker can gain unauthorized access to sensitive information.
Remediation
Upgrade LMS by Masteriyo to version 1.6.8 or higher to fix the vulnerability.
Source: ProjectDiscovery