Extension WordPress

Vulnérabilités Tutor LMS – eLearning and online course solution, page 4

Cette page rassemble les failles publiées pour Tutor LMS – eLearning and online course solution, leurs plages de versions affectées et les correctifs signalés dans la base locale.

73Vulnérabilités
2Critiques
73Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Tutor LMS – eLearning and online course solution

73 fiches

CVE-2021-24186 Élevée · 8,8
Tutor LMS – eLearning and online course solution

Tutor LMS <=1.8.2 – SQL Injection via tutor_answering_quiz_question/get_answer_by_id

The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.

Versions affectées

[*, 1.8.3)

Correctif

1.8.3

Publication

15/03/2021

CVE-2021-24184 Élevée · 8,8
Tutor LMS – eLearning and online course solution

Tutor LMS – eLearning and online course solution <= 1.7.6 – Unprotected AJAX including Privilege Escalation

Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to modify course information and elevate their privileges among many other actions.

Versions affectées

[*, 1.7.7)

Correctif

1.7.7

Publication

15/03/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités