go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

WisdomGarden Tronclass ilearn - Broken Access Control

TVN ID TVN-202311012
CVE ID AC2023000030
CVSS 6.5 (Medium)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products WisdomGarden Tronclass ilearn : 1.62.41849-hotfix-v1-62-84ccf1a5
Description WisdomGarden Tronclass ilearn is an e-learning platform, it has improper access control when uploading file. An authenticated remote attacker with general user privilege can exploit this vulnerability to access files belonging to other users by modifying the specific ID within URL.
Solution Update to the latest version
Credit TU
Public Date 2023-11-03
Top