Home
LOW: 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:NDefault status
unaffected
Any version before 0.57.5
affected
Description
CodeLit CourseLit before 0.57.5 allows Parameter Tampering via a payment plan associated with the wrong entity.
Problem types
CWE-472 External Control of Assumed-Immutable Web Parameter
Product status
Any version before 0.57.5
References
github.com/...mmits/5e11094df938e08485d0ab8aec2722c237ba0496
github.com/codelitdev/courselit/releases/tag/v0.57.5