The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 was affected by an IDOR issue, allowing students to see other student answers and grades
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/d45bb744-4a0d-4af0-aa16-71f7e3ea6e00 | third party advisory exploit |
https://make.lifterlms.com/2021/05/17/lifterlms-version-4-21-2/ | release notes vendor advisory |