The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.
History

Mon, 07 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:automattic:sensei_lms:*:*:*:*:*:wordpress:*:*

Wed, 04 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Automattic
Automattic sensei Lms
CPEs cpe:2.3:a:automattic:sensei_lms:*:*:*:*:*:*:*:*
Vendors & Products Automattic
Automattic sensei Lms
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Sep 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates.
Title Sensei LMS < 4.24.2 - Unauthenticated Email Template Leak
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-09-04T06:00:04.429Z

Updated: 2024-09-04T14:17:10.670Z

Reserved: 2024-08-14T08:29:31.987Z

Link: CVE-2024-7786

cve-icon Vulnrichment

Updated: 2024-09-04T14:16:53.856Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-04T06:15:17.600

Modified: 2024-10-07T17:46:08.943

Link: CVE-2024-7786

cve-icon Redhat

No data.