PT-2024-38746 · Viwis Lms · Viwis Lms
Ralph Meier
·
Published
2024-11-13
·
Updated
2025-01-08
·
CVE-2024-8001
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
VIWIS LMS version 9.11
Description:
A critical issue was found in the Print Handler component, leading to missing authorization. This allows a user with the role learner to access the entire exam, including solutions, in the web application using the administrative print function with an active session before and after an exam slot. The attack can be launched remotely.
Recommendations:
For VIWIS LMS version 9.11, apply a patch to fix this issue. As a temporary workaround, consider restricting access to the administrative print function for users with the learner role until a patch is available.
Fix
Incorrect Authorization
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Viwis Lms