6.5
CVE-2023-3345
- EPSS 64.84%
- Veröffentlicht 31.07.2023 10:15:10
- Zuletzt bearbeitet 10.06.2025 11:56:01
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Masteriyo - LMS for WordPress <= 1.6.7 - Sensitive Information Exposure
The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students
Mögliche Gegenmaßnahme
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education: Update to version 1.6.8, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education
Version
[*, 1.6.8)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Themegrill ≫ Masteriyo SwPlatformwordpress Version < 1.6.8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 64.84% | 0.984 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|