Impact
The vulnerability is an Insecure Direct Object Reference that allows a subscriber to request resources belonging to other subscribers through manipulated request parameters. This can lead to disclosure of private information without proper authorization. The weakness is identified as CWE-639, a classic authorization bypass.
Affected Systems
The vulnerability affects deployments of the Masteriyo – LMS plugin version 2.3.1 or earlier. The issue is resolved in version 2.3.2 and later.
Risk and Exploitability
The CVSS score is 5.4 indicating medium severity, and the EPSS score is less than 1% suggesting a low probability of exploitation at the moment. It is not listed in CISA KEV. The attack vector likely requires crafted HTTP requests or browser actions that change a resource identifier in the URL or POST data. Successful exploitation grants access to another subscriber’s data but does not provide code execution or broader system compromise.
OpenCVE Enrichment