PT-2022-18187 · Sourcecodester · Sourcecodester Simple E-Learning System

Xpn2100

·

Published

2022-08-08

·

Updated

2022-08-11

·

CVE-2022-2704

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Simple E-Learning System (affected versions not specified)
Description A vulnerability was found in the SourceCodester Simple E-Learning System, affecting the file downloadFiles.php. The manipulation of the download argument leads to information disclosure. The attack can be initiated remotely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-2704

Affected Products

Sourcecodester Simple E-Learning System