CVE Vulnerabilities

CVE-2023-3345

Published: Jul 31, 2023 | Modified: Nov 07, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The LMS by Masteriyo WordPress plugin before 1.6.8 does not properly safeguards sensitive user information, like other users email addresses, making it possible for any students to leak them via some of the plugins REST API endpoints.

Affected Software

Name Vendor Start Version End Version
Masteriyo Masteriyo * 1.6.8 (excluding)

References