CVE-2024-37093: WordPress MasterStudy LMS plugin <= 3.2.1 - Cross Site Request Forgery (CSRF) vulnerability
Published Jan 2, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Cross Site Request Forgery.This issue affects MasterStudy LMS: from n/a through <= 3.2.1.
Affected Software
3 affected components
StylemixThemes MasterStudy LMS WordPress<3.2.2
StylemixThemes MasterStudy LMS<=3.2.1
WordPress MasterStudy LMS WordPress Plugin<=3.2.1
Remediation
Information
Update the WordPress MasterStudy LMS plugin to the latest available version (at least 3.2.2).
Event History
Jan 2, 2025
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37093?
CVE-2024-37093 is classified as a Cross-Site Request Forgery (CSRF) vulnerability in the MasterStudy LMS.
2
How do I fix CVE-2024-37093?
To fix CVE-2024-37093, it is recommended to update the MasterStudy LMS to version 3.2.2 or later.
3
What software is affected by CVE-2024-37093?
CVE-2024-37093 affects MasterStudy LMS versions up to and including 3.2.1.
4
What types of attacks can exploit CVE-2024-37093?
CVE-2024-37093 can be exploited through Cross-Site Request Forgery (CSRF) attacks.
5
Is there a patch available for CVE-2024-37093?
Yes, a patch is available by updating MasterStudy LMS to version 3.2.2 or later.