What the vulnerability does
01Description
Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State. This issue affects MasterStudy LMS: from n/a through 3.7.39.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State. This issue affects MasterStudy LMS: from n/a through 3.7.39.
Explanation of Vulnerability in Simple Terms
MasterStudy LMS versions up to 3.7.39 do not properly verify the authenticity of data, allowing an attacker to modify information without detection. The vulnerability requires no authentication or user interaction and can be exploited over the network. This affects the integrity of course content, user records, or other critical data stored in the LMS.
What an attacker can do
Modify data in the LMS without proper verification, such as course content or user records.
Potential impact on your site
Course content, grades, user data, or other LMS records could be altered by an attacker without your knowledge.
Conditions required to exploit
Network access to the LMS; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities