Home

Description

CodeLit CourseLit before 0.57.5 allows Parameter Tampering via a payment plan associated with the wrong entity.

PUBLISHED Reserved 2025-04-11 | Published 2025-04-11 | Updated 2025-04-11 | Assigner mitre




LOW: 3.1CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Problem types

CWE-472 External Control of Assumed-Immutable Web Parameter

Product status

Default status
unaffected

Any version before 0.57.5
affected

References

github.com/...mmits/5e11094df938e08485d0ab8aec2722c237ba0496

github.com/codelitdev/courselit/releases/tag/v0.57.5

cve.org (CVE-2025-32816)

nvd.nist.gov (CVE-2025-32816)

Download JSON