Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2023-3345

Description

The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students

POC

Reference

- https://wpscan.com/vulnerability/0d07423e-98d2-43a3-824d-562747a3d65a

Github

- https://github.com/20142995/nuclei-templates