7.5
CVSSv2

CVE-2019-15896

Published: 10/09/2019 Updated: 21/07/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in the LifterLMS plugin up to and including 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (administrator account creation), website redirection, and stored XSS.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lifterlms lifterlms

Github Repositories

LifterLMS <= 3.34.5 - Unauthenticated Options Import

CVE-2019-15896 LifterLMS &lt;= 3345 - Unauthenticated Options Import Description Unauthenticated Options Import, which could lead to Website Redirection Administrator Account Creation Content Injection Stored XSS The issues have been reported as fixed in 3350 However v3351 added additional input sanitisation and filtering How to use $ python3 CVE-2019-1589