LearnPress WordPress 插件在 4.4.6 版本之前存在一个对象级授权失效(broken object-level authorization)漏洞。该漏洞允许拥有“讲师”(Instructor)角色的已认证攻击者,通过利用答案插入路径中缺失的属主检查,向其他讲师所属的测验题目中添加答案。攻击者可以在插入答案时提供任意的题目标识符,从而绕过讲师边界限制,对其未拥有的课程中的测验内容进行永久性修改。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ThimPress | LearnPress | < 4.4.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ThimPress | LearnPress | 0 ~ 4.4.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet