First published: Mon May 13 2024(Updated: )
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.25.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Creativeitem Academy LMS | <=1.9.25 | |
WordPress Academy LMS plugin | <=1.9.25 | |
kodezen Academy LMS | <1.9.26 |
Update to 1.9.26 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-35171 is considered high due to the exposure of sensitive information to unauthorized actors.
To fix CVE-2024-35171, upgrade to the latest version of Academy LMS or the Academy LMS plugin beyond version 1.9.25.
CVE-2024-35171 affects Academy LMS versions up to and including 1.9.25.
CVE-2024-35171 is classified as an exposure of sensitive information vulnerability.
All users of Academy LMS versions up to 1.9.25 could be impacted by CVE-2024-35171 if sensitive information is improperly exposed.