What the vulnerability does
01Description
Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3.
Explanation of Vulnerability in Simple Terms
LearnPress versions up to 4.2.3 lack proper authorization checks, allowing unauthenticated attackers to read, modify, or delete sensitive data via network requests. The vulnerability affects confidentiality, integrity, and availability of the learning platform. Update to version 4.4.1 or later to remediate.
What an attacker can do
Read, modify, or delete data without logging in or having permission to do so.
Potential impact on your site
Unauthorized users can access student records, course content, grades, and other sensitive learning data.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities