Record summary

CVE-2023-3345 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.

Description

The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 30, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

LMS by Masteriyo

Default status: unaffected

CVE ListBefore 1.6.8affected

Nuclei templates

1
ProjectDiscoveryMEDIUMLMS by Masteriyo < 1.6.8 - Information ExposureCVSS 6.5

The plugin does not properly safeguards sensitive user information, like other user's email addresses, making it possible for any students to leak them via some of the plugin's REST API endpoints.

Impact

An attacker can gain unauthorized access to sensitive information.

Remediation

Upgrade LMS by Masteriyo to version 1.6.8 or higher to fix the vulnerability.

WeaknessesCWE-200
AuthorsDhiyaneshDK
Template tagscve2023cvewp-pluginwpwordpressexposureauthenticatedlearning-management-systemwpscanmasteriyovuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:masteriyo:masteriyo:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2