Vulnerabilities > CVE-2018-16971 - Authorization Bypass Through User-Controlled Key vulnerability in Wisetail Learning Management System

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
wisetail
CWE-639

Summary

Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to access non-purchased course contents (quiz / test) via a modified id parameter.

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/149356/wle4116-disclose.txt
idPACKETSTORM:149356
last seen2018-09-14
published2018-09-13
reporterS. M. Zia Ur Rashid
sourcehttps://packetstormsecurity.com/files/149356/Wisetail-Learning-Ecosystem-4.11.6-Insecure-Direct-Object-Reference.html
titleWisetail Learning Ecosystem 4.11.6 Insecure Direct Object Reference