漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
LearnPress < 4.3.7 - Unauthenticated Sensitive User Information Disclosure via REST API
Vulnerability Description
The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allowing unauthenticated visitors to retrieve each returned user's roles, full capabilities map, extra capabilities, locale, and registration date via a crafted request
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Thimpress learnpress 授权问题漏洞
Vulnerability Description
thimpress learnpress是thimpress公司开源的一套搭建学习管理系统的方案。 Thimpress learnpress 4.3.7之前版本存在安全漏洞,该漏洞源于REST端点未正确限制`edit`环境,导致未经验证的访问者可通过特制请求检索每个返回用户的角色、完整权限映射、额外权限、语言环境和注册日期。
CVSS Information
N/A
Vulnerability Type
N/A