PT-2026-97710 · WordPress · Masteriyo - Lms
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Masteriyo LMS versions prior to 3.4.2
Description
An issue exists where access to quiz answer keys is not properly restricted. This allows any authenticated user, including students, to retrieve correct answers for any quiz on the site, regardless of whether they are enrolled in the associated course. The system only redacts answers for a specific list of question types, meaning answers for all other types are returned in full to any user capable of viewing the questions.
Recommendations
Update Masteriyo LMS to version 3.4.2 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Masteriyo - Lms