Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-1209. PoCs published by karlemilnikka. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2024-1209, an information exposure vulnerability in LearnDash LMS. It explains how unauthenticated users can access uploaded assignments via the REST API and includes patch details and timeline.
Description
The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2024-1209, an information exposure vulnerability in LearnDash LMS. It explains how unauthenticated users can access uploaded assignments via the REST API and includes patch details and timeline.
Nuclei Templates (1)
http.html:/wp-content/plugins/sfwd-lms
body=/wp-content/plugins/sfwd-lms
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N