CVE-2023-3345: LMS by Masteriyo < 1.6.8 - Information Exposure

CVE-2023-3345: LMS by Masteriyo < 1.6.8 - Information Exposure-渗透云记 - 专注于网络安全与技术分享
CVE-2023-3345: LMS by Masteriyo < 1.6.8 - Information Exposure
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2023-3345: LMS by Masteriyo < 1.6.8 – Information Exposure

漏洞描述

The plugin does not properly safeguards sensitive user information, like other user's email addresses, making it possible for any students to leak them via some of the plugin's REST API endpoints.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享