CVE-2021-24185: Tutor LMS < 1.7.7 - SQL Injection via tutor_place_rating
Published Apr 5, 2021
·Updated
The tutorplacerating AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.
Affected Software
1 affected component
Themeum Tutor Lms Wordpress<1.7.7
Event History
Apr 5, 2021
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-24185?
CVE-2021-24185 is a vulnerability in the Tutor LMS WordPress plugin that allows for blind and time-based SQL injections.
2
What is the severity of CVE-2021-24185?
The severity of CVE-2021-24185 is medium, with a CVSS score of 6.5.
3
How can CVE-2021-24185 be exploited?
CVE-2021-24185 can be exploited by students using blind and time-based SQL injections.
4
How can I fix CVE-2021-24185?
To fix CVE-2021-24185, update the Tutor LMS WordPress plugin to version 1.7.7 or later.
5
Where can I find more information about CVE-2021-24185?
More information about CVE-2021-24185 can be found at the following references: [link1], [link2].