Masteriyo – LMS < 1.7.4 – Insecure Direct Object Reference
Discription
Description The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.7.3 via the REST API due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view other users course…Read More
References
Back to Main