First published: Fri Feb 03 2023(Updated: )
A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Creativeitem Academy LMS | <5.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-47132.
The severity of CVE-2022-47132 is high with a CVSS score of 8.8.
The vulnerability allows attackers to arbitrarily add Administrator users.
To fix the vulnerability, update to Academy LMS version 5.10 or higher.
Yes, you can find additional information on this vulnerability at the following references: [https://portswigger.net/web-security/csrf](https://portswigger.net/web-security/csrf), [https://www.linkedin.com/in/xvinicius/](https://www.linkedin.com/in/xvinicius/), [https://xpsec.co/blog/academy-lms-5-10-add-admin-csrf](https://xpsec.co/blog/academy-lms-5-10-add-admin-csrf).