Vulnerabilities > CVE-2018-16971 - Authorization Bypass Through User-Controlled Key vulnerability in Wisetail Learning Management System
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to access non-purchased course contents (quiz / test) via a modified id parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |
Common Weakness Enumeration (CWE)
Packetstorm
data source | https://packetstormsecurity.com/files/download/149356/wle4116-disclose.txt |
id | PACKETSTORM:149356 |
last seen | 2018-09-14 |
published | 2018-09-13 |
reporter | S. M. Zia Ur Rashid |
source | https://packetstormsecurity.com/files/149356/Wisetail-Learning-Ecosystem-4.11.6-Insecure-Direct-Object-Reference.html |
title | Wisetail Learning Ecosystem 4.11.6 Insecure Direct Object Reference |