Coursemill Learning Management System (LMS) 6.6 does not properly restrict JSP function calls, which allows remote authenticated users to perform arbitrary JSP operations by leveraging the Student role and providing an op parameter.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
http://www.kb.cert.org/vuls/id/960908 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: certcc
Published: 2013-09-06T10:00:00Z
Updated: 2024-09-17T02:01:10.784Z
Reserved: 2013-05-21T00:00:00Z
Link: CVE-2013-3601
Vulnrichment
No data.
NVD
Status : Modified
Published: 2013-09-06T11:15:37.287
Modified: 2024-11-21T01:53:57.960
Link: CVE-2013-3601
Redhat
No data.