What the vulnerability does
01Description
Missing Authorization vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 1.9.16.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 1.9.16.
Explanation of Vulnerability in Simple Terms
Academy LMS versions up to 1.9.16 fail to properly check user permissions before allowing access to certain functions. A logged-in user with low privileges can read sensitive data or make unauthorized changes to the site. The vulnerability requires an active user account but no special interaction from a victim.
What an attacker can do
Read sensitive data and make unauthorized changes to the site as a low-privilege user.
Potential impact on your site
Unauthorized users can access or modify data they should not be able to reach, compromising data confidentiality and integrity.
Conditions required to exploit
Attacker must have a valid user account with low privileges on the site.
Key dates
External resources
Related vulnerabilities