PT-2013-4506 · Trivantis · Coursemill Learning Management System

Mike Czumak

·

Published

2013-09-06

·

Updated

2013-09-06

·

CVE-2013-3600

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Coursemill Learning Management System (LMS) version 6.6
Description The issue allows remote authenticated users to gain privileges via a modified userid value to unspecified functions.
Recommendations For version 6.6, consider restricting access to the affected functions until a patch is available. As a temporary workaround, avoid using modified userid values in the system to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3600

Affected Products

Coursemill Learning Management System