First published: Mon Apr 05 2021(Updated: )
The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Themeum Tutor Lms | <1.7.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-24181.
The affected software is the Tutor LMS - eLearning and online course solution WordPress plugin before version 1.7.7.
The severity of CVE-2021-24181 is medium with a severity value of 6.5.
The CWE classification of this vulnerability is CWE-89 (SQL Injection).
The blind and time based SQL injections can be exploited by students.