ZeroHour

CVE-2021-42331

CVSS 3.1
5.4 medium
EPSS
<1%p49
Published
()
Modified
Description

The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’s privilege, remote attackers can access and edit other users’ tutorial schedule by crafting URL parameters.

Vendors
xinheinformation
Products
xinhe teaching platform system
Weakness
CWE-285, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.