WordPress 的 Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning 插件在所有 4.0.3 及以下版本中存在授权绕过漏洞。该漏洞源于插件未正确验证用户是否有权执行某项操作。因此,具有自定义权限级别及以上身份的已认证攻击者可以永久删除任意 Academy 课程中由任何用户(包括管理员)发布的课程评论及其回复,即使用户并未负责这些课程。 该漏洞可被任何至少在一个课程中注册为“学院讲师”的用户利用。攻击者通过自行提供 参数,即可绕过
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kodezen | Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning | 0 ~ 4.0.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet