SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-3601

Coursemill Learning Management System (LMS) 6.6 does not properly restrict JSP function calls, which allows remote authenticated users to perform arbitrary JSP operations by leveraging the Student role and providing an op parameter.

MEDIUM 6.0EPSS 1.03%

Does this matter?

Lower severity and a low EPSS score (1.03%). Track it; it rarely justifies an emergency change on its own.

Description

Coursemill Learning Management System (LMS) 6.6 does not properly restrict JSP function calls, which allows remote authenticated users to perform arbitrary JSP operations by leveraging the Student role and providing an op parameter.

CVSS 2.0
6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
EPSS
1.03% probability · 62th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
trivantis/coursemill learning management system
Source
cret@cert.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.