CVE-2019-15896
10.09.2019, 16:15
An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (administrator account creation), website redirection, and stored XSS.Enginsight
Vendor | Product | Version |
---|---|---|
lifterlms | lifterlms | 𝑥 ≤ 3.34.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References