First published: Mon Apr 05 2021(Updated: )
The tutor_place_rating AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Themeum Tutor Lms | <1.7.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24185 is a vulnerability in the Tutor LMS WordPress plugin that allows for blind and time-based SQL injections.
The severity of CVE-2021-24185 is medium, with a CVSS score of 6.5.
CVE-2021-24185 can be exploited by students using blind and time-based SQL injections.
To fix CVE-2021-24185, update the Tutor LMS WordPress plugin to version 1.7.7 or later.
More information about CVE-2021-24185 can be found at the following references: [link1], [link2].