CVE-2019-15896

An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (administrator account creation), website redirection, and stored XSS.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:lifterlms:lifterlms:*:*:*:*:*:wordpress:*:*

Information

Published : 2019-09-10 09:15

Updated : 2021-07-21 04:39


NVD link : CVE-2019-15896

Mitre link : CVE-2019-15896


JSON object : View

CWE
CWE-306

Missing Authentication for Critical Function

Advertisement

dedicated server usa

Products Affected

lifterlms

  • lifterlms