CVE-2018-16970

Severity CVSS v4.0:
Pending analysis
Type:
CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory
Publication date:
12/09/2018
Last modified:
21/11/2018

Description

Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to download non-purchased course files via a modified id parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wisetail:learning_management_system:*:*:*:*:*:*:*:* 4.11.6 (including)