CVE-2026-28145
Received Received - Intake

Insufficient Verification of Data Authenticity in MasterStudy LMS

Vulnerability report for CVE-2026-28145, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-31

Last updated on: 2026-07-31

Assigner: Patchstack

Description

Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State. This issue affects MasterStudy LMS: from n/a through 3.7.39.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-31
Last Modified
2026-07-31
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
stylemixthemes masterstudy_lms to 3.7.39 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in StylemixThemes MasterStudy LMS allows attackers to manipulate user state without proper verification of data authenticity. It exists in versions up to 3.7.39 and could enable unauthorized changes to user accounts or permissions.

Impact Analysis

An attacker could exploit this to alter user states, potentially gaining unauthorized access to accounts, modifying course enrollments, or changing user roles without detection.

Compliance Impact

This vulnerability may lead to unauthorized data access or modification, violating GDPR's integrity and confidentiality requirements and HIPAA's access controls, potentially resulting in compliance violations.

Mitigation Strategies

Update MasterStudy LMS to version 3.7.39 or later to address the vulnerability. Review user permissions and access controls to ensure proper data authenticity verification. Monitor system logs for unusual activity related to user state manipulation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-28145. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart