WPScan
How it worksPricing
Vulnerabilities
WordPressPluginsThemesStatsSubmit vulnerabilities
For developers
StatusAPI detailsCLI scanner
Contact
WPScan
How it worksPricing
Vulnerabilities
WordPressPluginsThemesStatsSubmit vulnerabilities
For developers
StatusAPI detailsCLI scanner
Contact

WordPress Plugin Vulnerabilities

LifterLMS < 4.21.2 - Access Other Student Grades/Answers via IDOR

Description

The plugin was affected by an IDOR issue, allowing students to see other student answers and grades

Proof of Concept

- Add 2 users with Student role for the scenario .
- Create A course With a quiz ( I picked True or Flase question for my quiz)
- Set Enrol on Free ( for the ease of scenario )
- Enrol into the Course with Student B and submit your answer to the Course .

The plugin will give a token like : https://soft-dream.myliftersite.com/quiz/%d8%ac%d9%85%d8%b9-quiz/?attempt_key=wYK To Check your answer was true or false.

Now Login as a Student A and Enroll in the Course. You can just use the URL https://soft-dream.myliftersite.com/quiz/%d8%ac%d9%85%d8%b9-quiz/?attempt_key=wYK and reach the Student B answer. 

Affects Plugins

lifterlms
Fixed in version 4.21.2

References

CVE
CVE-2021-24562
URL
https://make.lifterlms.com/2021/05/17/lifterlms-version-4-21-2/

Classification

Type

IDOR

OWASP top 10
A5: Broken Access Control
CWE
CWE-639

Miscellaneous

Original Researcher

Amirmuhammad vakili

Submitter

captain_hook

Submitter website
https://captainhoook.medium.com/
Verified

Yes

WPVDB ID
d45bb744-4a0d-4af0-aa16-71f7e3ea6e00

Timeline

Publicly Published

2021-05-17 (about 1 years ago)

Added

2021-07-22 (about 1 years ago)

Last Updated

2023-01-24 (about 1 months ago)

Our Other Services

WPScan WordPress Security Plugin
WPScan

Vulnerabilities

WordPressPluginsThemesOur StatsSubmit vulnerabilities

About

How it worksPricingWordPress pluginNewsContact

For Developers

StatusAPI detailsCLI scanner

Other

PrivacyTerms of serviceSubmission termsDisclosure policyPrivacy Notice for California Users
jetpackIn partnership with Jetpack
githubtwitterfacebook
Angithubendeavor
Work With Us