PT-2024-34387 · Adapt Learning · Adapt Learning Adapt Authoring Tool
Dos-M0Nk3Y
·
Published
2024-11-25
·
Updated
2024-12-04
·
CVE-2024-50671
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Adapt Learning Adapt Authoring Tool versions <= 0.11.3
Description:
The issue is related to incorrect access control, allowing attackers with Authenticated User roles to obtain email addresses via the "Get users" feature. This occurs due to a flaw in permission verification logic, where the wildcard character in permitted URLs grants unintended access to endpoints restricted to users with Super Admin roles, making it possible for attackers to disclose the email addresses of all users.
Recommendations:
For Adapt Learning Adapt Authoring Tool versions <= 0.11.3, update to a version that fixes the permission verification logic flaw to prevent unintended access to restricted endpoints. As a temporary workaround, consider restricting access to the "Get users" feature to only Super Admin roles until a patch is available.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adapt Learning Adapt Authoring Tool