CVE Vulnerabilities

CVE-2018-16970

Insertion of Sensitive Information into Externally-Accessible File or Directory

Published: Sep 12, 2018 | Modified: Nov 21, 2018
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to download non-purchased course files via a modified id parameter.

Weakness

The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.

Affected Software

Name Vendor Start Version End Version
Learning_management_system Wisetail * 4.11.6 (including)

Potential Mitigations

References