DT LMS – elearning(WordPress LMS 插件)在版本 1.1 及更早版本中存在数据可被未授权修改的漏洞。该漏洞源于多个 AJAX 处理函数(包括 、 和 )中缺少权限(capability)检查。这些处理函数注册在 钩子上,既没有进行权限检查,也没有进行 nonce 验证,且将用户提交的数据直接传递给 函数。这使得未认证的 attacker 能够覆盖 表中存储的任意插件选项值,包括联系人(Point-of-Contact)邮箱配置和皮肤/品牌设置,从而改变所有站点访客看到的 LMS 界面外
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| designthemes | DT LMS – elearning, WordPress LMS Plugin | 0 ~ 1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet