CVE-2021-24562: LifterLMS < 4.21.2 - Access Other Student Grades/Answers via IDOR
The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 was affected by an IDOR issue, allowing students to see other student answers and grades
Other sources
The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 was affected by an IDOR issue, allowing students to see other student answers and grades
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this LifterLMS plugin?
The vulnerability ID of this LifterLMS plugin is CVE-2021-24562.
What is the severity level of CVE-2021-24562?
The severity level of CVE-2021-24562 is high with a score of 7.5.
What is the description of CVE-2021-24562?
CVE-2021-24562 is an Insecure Direct Object Reference (IDOR) issue in the LMS by LifterLMS plugin, allowing students to see other student answers and grades.
Which version of the LMS by LifterLMS plugin is affected by CVE-2021-24562?
The LMS by LifterLMS plugin version up to and excluding 4.21.2 is affected by CVE-2021-24562.
How can I fix CVE-2021-24562?
To fix CVE-2021-24562, update the LMS by LifterLMS plugin to version 4.21.2 or later.