Extension WordPress

Vulnérabilités CLUEVO LMS, E-Learning Platform

Cette page rassemble les failles publiées pour CLUEVO LMS, E-Learning Platform, leurs plages de versions affectées et les correctifs signalés dans la base locale.

4Vulnérabilités
0Critiques
4Avec correctif
6,1CVSS maximal

Historique de sécurité

CVE et vulnérabilités de CLUEVO LMS, E-Learning Platform

4 fiches

CVE-2024-11444 Moyenne · 4,3
CLUEVO LMS, E-Learning Platform

CLUEVO LMS, E-Learning Platform <= 1.13.2 – Cross-Site Request Forgery to Module Deletion

The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.13.2. This is due to missing or incorrect nonce validation on the cluevo_render_module_ui() function. This makes it…

Versions affectées

*-1.13.2

Correctif

1.13.3

Publication

05/12/2024

CVE-2021-25029 Moyenne · 4,8
CLUEVO LMS, E-Learning Platform

CLUEVO E-Learning Platform <= 1.8.0 – Authenticated Cross-Site Scripting

The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed The CLUEVO E-Learning Platform…

Versions affectées

[*, 1.8.1)

Correctif

1.8.1

Publication

10/01/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités