CVE-2022-2563: Tutor LMS < 2.0.10 - Admin+ Stored Cross-Site Scripting
Published Oct 17, 2022
·Updated
The Tutor LMS WordPress plugin before 2.0.10 does not escape some course parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
1 affected component
Themeum Tutor Lms Wordpress<2.0.10
Event History
Oct 17, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-2563.
2
What is the severity of CVE-2022-2563?
CVE-2022-2563 has a severity rating of 4.8, which is considered medium.
3
What is the affected software of CVE-2022-2563?
The affected software of CVE-2022-2563 is the Tutor LMS WordPress plugin before version 2.0.10.
4
What is the description of CVE-2022-2563?
CVE-2022-2563 is a vulnerability in the Tutor LMS WordPress plugin that allows high privilege users to perform Stored Cross-Site Scripting attacks.
5
How can I fix the CVE-2022-2563 vulnerability?
To fix the CVE-2022-2563 vulnerability, update the Tutor LMS WordPress plugin to version 2.0.10 or later.