A vulnerability was found in VIWIS LMS 9.11. It has been classified as critical. Affected is an unknown function of the component Print Handler. The manipulation leads to missing authorization. It is possible to launch the attack remotely. A user with the role learner can use the administrative print function with an active session before and after an exam slot to access the entire exam including solutions in the web application. It is recommended to apply a patch to fix this issue.
History

Wed, 13 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Viwis
Viwis lms
CPEs cpe:2.3:a:viwis:lms:*:*:*:*:*:*:*:*
Vendors & Products Viwis
Viwis lms
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 13 Nov 2024 10:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in VIWIS LMS 9.11. It has been classified as critical. Affected is an unknown function of the component Print Handler. The manipulation leads to missing authorization. It is possible to launch the attack remotely. A user with the role learner can use the administrative print function with an active session before and after an exam slot to access the entire exam including solutions in the web application. It is recommended to apply a patch to fix this issue.
Title VIWIS LMS Print authorization
Weaknesses CWE-862
CWE-863
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-11-13T09:47:38.973Z

Updated: 2024-11-13T14:55:18.860Z

Reserved: 2024-08-20T08:04:18.419Z

Link: CVE-2024-8001

cve-icon Vulnrichment

Updated: 2024-11-13T14:54:59.460Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-13T10:15:04.593

Modified: 2024-11-13T17:01:16.850

Link: CVE-2024-8001

cve-icon Redhat

No data.