CVE Database
/

CVE-2022-2080

Back to search

CVE-2022-2080

Published: Aug 29, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to send messages to arbitrary private conversation via a IDOR attack. Note: Attackers are not able to see responses/messages between the teacher and student

VendorProductVersions

Unknown

Sensei LMS – Online Courses, Quizzes, & Learning

affected
4.5.2 - < 4.5.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now