# Masteriyo 插件 <= 1.7.3 - WordPress LMS 认证机制漏洞
## 概述
Masteriyo - LMS 存在一个认证绕过漏洞,允许未经授权的用户通过替代路径或通道访问课程进度信息。
## 影响版本
从 n/a 至 1.7.3 版本
## 细节
该漏洞利用了使用替代路径或通道绕过认证的机制,未授权用户能够访问课程进度信息。
## 影响
未经授权的用户可以访问课程进度信息,进而获取敏感数据或进行其他未经授权的操作。
是否为 Web 类漏洞: 是
判断理由:
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Masteriyo Masteriyo - LMS. Unauth access to course progress.This issue affects Masteriyo - LMS: from n/a through 1.7.3. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-33939.yaml | POC详情 |
标题: WordPress LMS by Masteriyo plugin <= 1.7.3 - Broken Authentication vulnerability - Patchstack -- 🔗来源链接
标签:vdb-entry
神龙速读:
### 关键信息
- **漏洞名称**: WordPress Masteriyo - LMS Plugin <= 1.7.3 is vulnerable to Broken Authentication
- **优先级**: Medium priority
- **CVE编号**: CVE-2023-53
- **风险**: Moderately dangerous and expected to become exploited.
- **受影响版本**: <= 1.7.3
- **修复版本**: 1.7.4
- **漏洞类型**: Broken Authentication
- **描述**: This can be abused by a malicious actor to perform action which normally should only be able to be executed by higher privileged users. These actions might allow the malicious actor to gain admin access to the website.
- **已知被利用**: Known to be exploited!
- **解决方案**:
- Automatically mitigate vulnerabilities and keep your websites safe using Patchstack's virtual patch.
- Update to version 1.7.4 or later.
- **报告者**: Steven Julian
- **发布时间**: 30 April 2024
暂无评论