CVE-2024-8001

A vulnerability was found in VIWIS LMS 9.11. It has been classified as critical. Affected is an unknown function of the component Print Handler. The manipulation leads to missing authorization. It is possible to launch the attack remotely. A user with the role learner can use the administrative print function with an active session before and after an exam slot to access the entire exam including solutions in the web application. It is recommended to apply a patch to fix this issue.
References
Link Resource
https://vuldb.com/?ctiid.284352 Permissions Required
https://vuldb.com/?id.284352 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:viwis:learning_management_system:9.11:*:*:*:*:*:*:*

History

19 Nov 2024, 15:41

Type Values Removed Values Added
CVSS v2 : 5.0
v3 : 5.3
v2 : 5.0
v3 : 4.3
Summary
  • (es) Se ha encontrado una vulnerabilidad en VIWIS LMS 9.11. Se ha clasificado como crítica. Se ve afectada una función desconocida del componente Print Handler. La manipulación provoca la falta de autorización. Es posible lanzar el ataque de forma remota. Un usuario con el rol de alumno puede utilizar la función de impresión administrativa con una sesión activa antes y después de un espacio de examen para acceder a todo el examen, incluidas las soluciones en la aplicación web. Se recomienda aplicar un parche para solucionar este problema.
CPE cpe:2.3:a:viwis:learning_management_system:9.11:*:*:*:*:*:*:*
First Time Viwis
Viwis learning Management System
References () https://vuldb.com/?ctiid.284352 - () https://vuldb.com/?ctiid.284352 - Permissions Required
References () https://vuldb.com/?id.284352 - () https://vuldb.com/?id.284352 - Third Party Advisory

13 Nov 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-13 10:15

Updated : 2024-11-19 15:41


NVD link : CVE-2024-8001

Mitre link : CVE-2024-8001

CVE.ORG link : CVE-2024-8001


JSON object : View

Products Affected

viwis

  • learning_management_system
CWE
CWE-862

Missing Authorization

CWE-863

Incorrect Authorization