The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students
Metrics
Affected Vendors & Products
References
History
Fri, 30 Aug 2024 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The LMS by Masteriyo WordPress plugin before 1.6.8 does not properly safeguards sensitive user information, like other user's email addresses, making it possible for any students to leak them via some of the plugin's REST API endpoints. | The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students |
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2023-07-31T09:37:36.423Z
Updated: 2024-08-30T13:34:18.185Z
Reserved: 2023-06-20T19:06:59.169Z
Link: CVE-2023-3345
Vulnrichment
Updated: 2024-08-02T06:55:02.693Z
NVD
Status : Modified
Published: 2023-07-31T10:15:10.653
Modified: 2024-11-21T08:17:03.907
Link: CVE-2023-3345
Redhat
No data.