CVE-2023-49829: WordPress Tutor LMS Plugin <= 2.2.4 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS – eLearning and online course solution allows Stored XSS.This issue affects Tutor LMS – eLearning and online course solution: from n/a through 2.2.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49829?
CVE-2023-49829 has a high severity level due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2023-49829?
To fix CVE-2023-49829, update Themeum Tutor LMS to the latest version, ensuring it is beyond version 2.2.4.
Who is affected by CVE-2023-49829?
CVE-2023-49829 affects users of Themeum Tutor LMS versions up to and including 2.2.4.
What type of vulnerability is CVE-2023-49829?
CVE-2023-49829 is classified as an improper neutralization of input vulnerability resulting in stored cross-site scripting (XSS).
What are the consequences of not mitigating CVE-2023-49829?
Failing to mitigate CVE-2023-49829 could allow attackers to execute malicious scripts in users' browsers, compromising sensitive data.