7.5
CVE-2024-7786
- EPSS 70.48%
- Veröffentlicht 04.09.2024 06:15:17
- Zuletzt bearbeitet 07.10.2024 17:46:08
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Sensei LMS < 4.24.2 - Unauthenticated Email Template Leak
Sensei LMS – Online Courses, Quizzes, & Learning <= 4.24.1 - Unauthenticated Email Template Disclosure
The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.
Mögliche Gegenmaßnahme
Sensei LMS – Online Courses, Quizzes, & Learning: Update to version 4.24.2, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Automattic ≫ Sensei Lms SwPlatformwordpress Version < 4.24.2
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Sensei LMS – Online Courses, Quizzes, & Learning
Version
*-4.24.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 70.48% | 0.986 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|