Security Breach In LMS - Question | JoomShaper
SP Page Builder 6 is Here! Learn More →

Security Breach In LMS

Yann TASSY

Yann TASSY

Extension 1 year ago

I'm using LMS plug-in more and more. I found a security issue.

Steps to reproduce:

  • Create an LMS purchases menu item
  • Create LMS Certificates for somes students
  • Log in with the account of one of the students
  • Access their certificate
  • In the URL, change the value of the certificate ID. (?view=certificate&id=xxxxx) and set another id
  • The student can access all the certificates of all the other students.

Thanks ! Yann

1
9 Answers
Rashida Rahman
Rashida Rahman
Accepted Answer
Support Agent 1 year ago #164430

Hi there!

Thanks for reporting this. We will check and forward it to the developer team for resolution.

Best Regards

0
Yann TASSY
Yann TASSY
Accepted Answer
1 year ago #164432

Thank you a lot ! Yann

0
Rashida Rahman
Rashida Rahman
Accepted Answer
Support Agent 1 year ago #164438

Hi Yann,

We have released a security patch for SP LMS. You can find it here:

https://www.joomshaper.com/downloads/extension/sp-lms

Please try this new build and let us know if it resolves the issue for you.

Best Regards

1
Yann TASSY
Yann TASSY
Accepted Answer
1 year ago #164440

I've just tested it and it works!

Thanks for being so quick! Yann

0
Rashida Rahman
Rashida Rahman
Accepted Answer
Support Agent 1 year ago #164511

Thanks for letting us know about your feedback:)

Have a nice day!

0
Yann TASSY
Yann TASSY
Accepted Answer
1 year ago #164557

Done !

0
Rashida Rahman
Rashida Rahman
Accepted Answer
Support Agent 1 year ago #164593

Hello,

Thanks for your consideration:)

Where did you give us review, please? Should I find it on your name: "Yann TASSY"?

Best Regards

0
Yann TASSY
Yann TASSY
Accepted Answer
1 year ago #164604

Yes "Yann Tassy"

https://www.trustpilot.com/reviews/66ba1b96a230d90972bcd1a3

In Joomla, it is in "Pending Confirmation"

0
Rashida Rahman
Rashida Rahman
Accepted Answer
Support Agent 1 year ago #164607

Thankful for this response:)

0