Vulnerability Description
The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 was affected by an IDOR issue, allowing students to see other student answers and grades
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lifterlms | Lifterlms | < 4.21.2 |
Related Weaknesses (CWE)
References
- https://make.lifterlms.com/2021/05/17/lifterlms-version-4-21-2/Release NotesVendor Advisory
- https://wpscan.com/vulnerability/d45bb744-4a0d-4af0-aa16-71f7e3ea6e00ExploitThird Party Advisory
- https://make.lifterlms.com/2021/05/17/lifterlms-version-4-21-2/Release NotesVendor Advisory
- https://wpscan.com/vulnerability/d45bb744-4a0d-4af0-aa16-71f7e3ea6e00ExploitThird Party Advisory
FAQ
What is CVE-2021-24562?
CVE-2021-24562 is a vulnerability with a CVSS score of 7.5 (HIGH). The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 was affected by an IDOR issue, allowing students to see other student answers an...
How severe is CVE-2021-24562?
CVE-2021-24562 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24562?
Check the references section above for vendor advisories and patch information. Affected products include: Lifterlms Lifterlms.