CVE-2022-2080: Sensei LMS < 4.5.2 - Arbitrary Private Message Sending via IDOR
The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to send messages to arbitrary private conversation via a IDOR attack. Note: Attackers are not able to see responses/messages between the teacher and student
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-2080.
What is the severity of CVE-2022-2080?
The severity of CVE-2022-2080 is medium with a CVSS score of 4.3.
What software is affected by CVE-2022-2080?
The Sensei LMS WordPress plugin version up to exclusive 4.5.2 is affected by CVE-2022-2080.
How does CVE-2022-2080 impact private messages?
CVE-2022-2080 allows any authenticated user to send messages to arbitrary private conversations via an IDOR attack, bypassing the sender verification.
Can attackers see responses/messages using CVE-2022-2080?
No, attackers exploiting CVE-2022-2080 are not able to see responses or messages.