What the vulnerability does
01Description
Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
Explanation of Vulnerability in Simple Terms
Masteriyo LMS versions up to 2.3.1 contain an authorization flaw that allows authenticated users to modify or disable site features. An attacker with a low-privilege account can alter data integrity or degrade service availability without elevated permissions. The vulnerability requires network access and valid login credentials but no user interaction beyond the initial authentication.
What an attacker can do
Modify site data or degrade availability as a low-privilege authenticated user.
Potential impact on your site
Authenticated users can alter course data or disrupt service availability without admin approval.
Conditions required to exploit
Valid login credentials with low-level account privileges; network access to the site.
Key dates
External resources
Related vulnerabilities