CVE-2023-0236: Tutor LMS < 2.0.10 - Reflected Cross-Site Scripting
Published Feb 6, 2023
·Updated
The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the resetkey and userid parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
1 affected component
Themeum Tutor Lms Wordpress<2.0.10
Event History
Feb 6, 2023
CVE Published
via MITRE·07:59 PM
Data Sourced
via MITRE·07:59 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-0236.
2
What is the affected software?
The affected software is the Tutor LMS WordPress plugin, version up to 2.0.10.
3
What is the severity of CVE-2023-0236?
The severity of CVE-2023-0236 is medium, with a CVSS score of 6.1.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-79.
5
How can I fix CVE-2023-0236?
To fix CVE-2023-0236, update the Tutor LMS WordPress plugin to version 2.0.10 or later.