6.5
CVE-2023-3345
- EPSS 1.93%
- Veröffentlicht 31.07.2023 10:15:10
- Zuletzt bearbeitet 10.06.2025 11:56:01
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
LMS by Masteriyo < 1.6.8 - Information Exposure
Masteriyo - LMS for WordPress <= 1.6.7 - Sensitive Information Exposure
The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students
Mögliche Gegenmaßnahme
Masteriyo LMS – LMS Course Builder, Quizzes & Certificates: Update to version 1.6.8, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Themegrill ≫ Masteriyo SwPlatformwordpress Version < 1.6.8
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Masteriyo LMS – LMS Course Builder, Quizzes & Certificates
Version
[*, 1.6.8)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.93% | 0.773 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
https://wpscan.com/vulnerability/0d07423e-98d2-43a3-824d-562747a3d65a
https://www.wordfence.com/threat-intel/vulnerabilities/id/5e8933b8-1e09-4cd7-8206-711cc0716dba