What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4.
Explanation of Vulnerability in Simple Terms
Academy LMS versions up to 2.0.4 contain an authorization flaw that allows authenticated users to modify data they should not have access to. The vulnerability requires a valid user account and network access but does not require user interaction. Integrity of site data can be compromised, though confidentiality and availability are not directly affected.
What an attacker can do
Modify data or settings in Academy LMS that should be restricted to other users or administrators.
Potential impact on your site
Unauthorized changes to course content, user records, or site configuration by authenticated users with limited permissions.
Conditions required to exploit
Attacker must have a valid Academy LMS user account with low-level privileges.
Key dates
External resources
Related vulnerabilities