Lucene search

K
wpexploitVeshraj GhimireWPEX-ID:ABA3DD58-7A8E-4129-ADD5-4DD5972C0426
HistoryAug 04, 2022 - 12:00 a.m.

Sensei LMS < 4.5.0 - Unauthenticated Private Messages Disclosure via Rest API

2022-08-0400:00:00
Veshraj Ghimire
91
sensei lms
unauthenticated
private messages
disclosure
rest api
exploit

EPSS

0.005

Percentile

76.6%

The plugin does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers

https://example.com/wp-json/wp/v2/sensei-messages/<numericID>

EPSS

0.005

Percentile

76.6%

Related for WPEX-ID:ABA3DD58-7A8E-4129-ADD5-4DD5972C0426