NA

CVE-2022-47615

Published: 26/01/2023 Updated: 07/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

thimpress learnpress

Github Repositories

LearnPress Plugin < 4.2.0 - Unauthenticated LFI Description

CVE-2022-47615 LearnPress Plugin &lt; 420 - Unauthenticated LFI Description Description The plugin does not validate various parameters in the lp/v1/courses/archive-course REST endpoints before using them in include statement, which could lead to LFI issues How to use $ python3 exploitpy -u wordpresslan -f ///etc/passwd root:x:0:0:root:/root:/bin/bash daem