WordPress MasterStudy是WordPress基金会开源的一个学习管理系统组件。 WordPress MasterStudy 3.7.14及之前版本存在授权问题漏洞,该漏洞源于stm_lms_delete_cover()函数缺少对file_id参数的所有权验证,导致不安全的直接对象引用,可能使具有Instructor级别及以上权限的认证攻击者通过枚举附件ID删除任意用户的附件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| stylemix | MasterStudy LMS WordPress Plugin – for Online Courses and Education | ≤ 3.7.23 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| stylemix | MasterStudy LMS WordPress Plugin – for Online Courses and Education | 0 ~ 3.7.23 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet