PT-2026-58007 · Kodezen+1 · Academy Lms+1
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution versions prior to 3.8.1
Description
An Insecure Direct Object Reference occurs via the 'save lesson note', 'get lesson note', and 'complete lesson video' AJAX handlers due to missing validation on a user controlled key. This allows authenticated attackers with Subscriber-level access or higher to read, overwrite, or delete private lesson notes of any other user, including administrators, and to falsify lesson-completion progress for arbitrary users.
Recommendations
Update the plugin to version 3.8.1 or later.
Fix
DoS
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Academy Lms
Academy