CVE-2023-25990: WordPress Tutor LMS plugin <= 2.1.10 - Multiple Tutor Instructor+ SQL Injection vulnerability
Published Nov 3, 2023
·Updated
A vulnerability in Themeum Tutor LMS tutor.This issue affects Tutor LMS: from n/a through <= 2.1.10.
Affected Software
1 affected component
Themeum Tutor Lms Wordpress<=2.1.10
Remediation
Information
Update to 2.2.0 or a higher version.
Event History
Nov 3, 2023
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2023-25990.
2
What is the severity of CVE-2023-25990?
The severity of CVE-2023-25990 is high with a CVSS score of 8.8.
3
What software is affected by CVE-2023-25990?
The Tutor LMS plugin version up to and including 2.1.10 for WordPress is affected by CVE-2023-25990.
4
What is the vulnerability description of CVE-2023-25990?
CVE-2023-25990 is an SQL Injection vulnerability in Themeum Tutor LMS, allowing an attacker to execute malicious SQL commands.
5
Is there a fix available for CVE-2023-25990?
Yes, a fix is available for CVE-2023-25990. Please refer to the provided reference for more information.