漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Insecure direct object reference vulnerability
Vulnerability Description
An insecure direct object reference vulnerability in Koollab LMS allowed an authenticated user to query the course completion progress of any other user without authorisation, disclosing private learning progress information.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
N/A
Vulnerability Title
Three Learning Koollab LMS 安全漏洞
Vulnerability Description
Three Learning Koollab LMS是Three Learning公司的一款学习管理系统。 Three Learning Koollab LMS 5.3.2版本存在安全漏洞,该漏洞源于不安全的直接对象引用,可能导致已认证用户查询其他用户的课程完成进度并泄露学习进度信息。
CVSS Information
N/A
Vulnerability Type
N/A