CVE-2021-24186: Tutor LMS < 1.8.3 - SQL Injection via tutor_answering_quiz_question/get_answer_by_id
The tutoransweringquizquestion/getanswerbyid function pair from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24186?
CVE-2021-24186 is a vulnerability in the Tutor LMS WordPress plugin that allows for UNION-based SQL injection.
How does CVE-2021-24186 affect Tutor LMS?
CVE-2021-24186 affects the tutor_answering_quiz_question/get_answer_by_id function pair in Tutor LMS versions before 1.8.3.
What is the severity rating of CVE-2021-24186?
CVE-2021-24186 has a severity rating of 6.5 (medium).
How can CVE-2021-24186 be exploited?
CVE-2021-24186 can be exploited by students to perform UNION-based SQL injection.
Are there any references for CVE-2021-24186?
Yes, you can find more information about CVE-2021-24186 at the following references: [Wordfence Blog](https://www.wordfence.com/blog/2021/03/several-vulnerabilities-patched-in-tutor-lms-plugin/) and [WPScan](https://wpscan.com/vulnerability/5f5c0c6c-6f76-4366-b590-0aab557f8c60).