PT-2013-4507 · Trivantis · Coursemill Learning Management System
Mike Czumak
·
Published
2013-09-06
·
Updated
2013-09-30
·
CVE-2013-3601
CVSS v2.0
6.0
Medium
| Vector | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Coursemill Learning Management System (LMS) version 6.6
Description
The issue allows remote authenticated users to perform arbitrary JSP operations by leveraging the Student role and providing an
op parameter. This is due to the system not properly restricting JSP function calls.Recommendations
For version 6.6, restrict access to JSP function calls for users with the Student role to prevent arbitrary operations. Consider temporarily disabling the
op parameter in affected JSP operations until a proper fix is applied.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coursemill Learning Management System