Vulnerabilities > Wisetail

DATE CVE VULNERABILITY TITLE RISK
2018-09-12 CVE-2018-16971 Authorization Bypass Through User-Controlled Key vulnerability in Wisetail Learning Management System
Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to access non-purchased course contents (quiz / test) via a modified id parameter.
network
low complexity
wisetail CWE-639
4.3
2018-09-12 CVE-2018-16970 File and Directory Information Exposure vulnerability in Wisetail Learning Management System
Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to download non-purchased course files via a modified id parameter.
network
low complexity
wisetail CWE-538
4.3