CVE Vulnerabilities

CVE-2021-42332

Published: Oct 15, 2021 | Modified: Aug 12, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The “List View” function of ShinHer StudyOnline System is not under authority control. After logging in with user’s privilege, remote attackers can access the content of other users’ message boards by crafting URL parameters.

Affected Software

Name Vendor Start Version End Version
Xinhe_teaching_platform_system Xinheinformation v2021 (including) v2021 (including)

References