4
CVSSv2

CVE-2018-16970

Published: 12/09/2018 Updated: 21/11/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to download non-purchased course files via a modified id parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wisetail learning management system

Exploits

Wisetail Learning Ecosystem (LE) versions up to 4116 suffer from multiple insecure direct object reference vulnerabilities that allow an attacker to download files and get access to the non-purchased course quiz test via a modified id parameter ...