ZeroHour

CVE-2021-24186

PoC ×2
CVSS 3.1
6.5 medium
EPSS
1%p68
Published
()
Modified
Description

The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.

Vendors
themeum
Products
tutor lms
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.