Extension WordPress

Vulnérabilités Tutor LMS – eLearning and online course solution, page 4

Cette page rassemble les failles publiées pour Tutor LMS – eLearning and online course solution, leurs plages de versions affectées et les correctifs signalés dans la base locale.

80Vulnérabilités
2Critiques
80Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Tutor LMS – eLearning and online course solution

80 fiches

CVE-2022-2563 Moyenne · 5,5
Tutor LMS – eLearning and online course solution

Tutor LMS <= 2.0.9 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Tutor LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the topic name and lesson name parameters in versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-2.0.9

Correctif

2.0.10

Publication

26/09/2022

Vulnérabilité Moyenne · 6,1
Tutor LMS – eLearning and online course solution

Tutor LMS – eLearning and online course solution 2.0.0-2.0.8 – Reflected Cross-Site Scripting

The Tutor LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions 2.0.0-2.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…

Versions affectées

2.0.0-2.0.8

Correctif

2.0.9

Publication

22/08/2022

CVE-2021-24186 Élevée · 8,8
Tutor LMS – eLearning and online course solution

Tutor LMS <=1.8.2 – SQL Injection via tutor_answering_quiz_question/get_answer_by_id

The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.

Versions affectées

[*, 1.8.3)

Correctif

1.8.3

Publication

15/03/2021

CVE-2021-24184 Élevée · 8,8
Tutor LMS – eLearning and online course solution

Tutor LMS – eLearning and online course solution <= 1.7.6 – Unprotected AJAX including Privilege Escalation

Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to modify course information and elevate their privileges among many other actions.

Versions affectées

[*, 1.7.7)

Correctif

1.7.7

Publication

15/03/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités