Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5hff-r5rf-v64j

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to modify course information and elevate their privileges among many other actions.

Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to modify course information and elevate their privileges among many other actions.

EPSS

Процентиль: 69%
0.00603
Низкий

8.8 High

CVSS3

Дефекты

CWE-269
CWE-862

Связанные уязвимости

CVSS3: 8.8
nvd
почти 5 лет назад

Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to modify course information and elevate their privileges among many other actions.

EPSS

Процентиль: 69%
0.00603
Низкий

8.8 High

CVSS3

Дефекты

CWE-269
CWE-862