Количество 3
Количество 3
CVE-2023-0236
The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
GHSA-qx7f-p25m-8c56
The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
BDU:2023-07311
Уязвимость плагина Tutor LMS системы управления содержимым сайта WordPress,позволяющая нарушителю выполнить произвольный код
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-0236 The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin | CVSS3: 6.1 | 20% Средний | около 3 лет назад | |
GHSA-qx7f-p25m-8c56 The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin | CVSS3: 6.1 | 20% Средний | около 3 лет назад | |
BDU:2023-07311 Уязвимость плагина Tutor LMS системы управления содержимым сайта WordPress,позволяющая нарушителю выполнить произвольный код | CVSS3: 6.1 | 20% Средний | около 3 лет назад |
Уязвимостей на страницу