vendor:
Masterstudy LMS
by:
Revan Arifio
6.1
CVSS
HIGH
Unauthenticated Instructor Account Creation
287
CWE
Product Name: Masterstudy LMS
Affected Version From: <= 3.0.17
Affected Version To:
Patch Exists: YES
Related CWE: CVE-2023-4278
CPE: a:wordpress:masterstudy_lms:3.0.17
Platforms Tested: Windows, Linux
2023
WordPress Plugin Masterstudy LMS – 3.0.17 – Unauthenticated Instructor Account Creation
This exploit allows an attacker to create an instructor account on the Wordpress Plugin Masterstudy LMS version 3.0.17 or earlier without authentication. The vulnerability is caused by improper input validation, which allows an attacker to bypass the registration process and create an instructor account with arbitrary credentials.
Mitigation:
Update to the latest version of the Masterstudy LMS plugin (version 3.0.18 or later) which addresses this vulnerability.