Описание
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Release NotesVendor Advisory
- ExploitThird Party AdvisoryVDB Entry
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.5.3 (исключая)
cpe:2.3:a:themeum:tutor_lms:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 91%
0.06895
Низкий
6.5 Medium
CVSS3
2.6 Low
CVSS2
Дефекты
CWE-352
Связанные уязвимости
github
больше 3 лет назад
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).
EPSS
Процентиль: 91%
0.06895
Низкий
6.5 Medium
CVSS3
2.6 Low
CVSS2
Дефекты
CWE-352