CVE-2024-37947: WordPress Tutor LMS plugin <= 2.7.2 - Cross Site Scripting (XSS) vulnerability
Published Jul 20, 2024
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themeum Tutor LMS allows Stored XSS.This issue affects Tutor LMS: from n/a through 2.7.2.
Affected Software
3 affected components
Themeum Tutor Lms Wordpress<2.7.3
Themeum Tutor LMS<=2.7.2
WordPress Tutor LMS<=2.7.2
Remediation
Information
Update to 2.7.3 or a higher version.
Event History
Jul 20, 2024
CVE Published
via MITRE·08:31 AM
Data Sourced
via MITRE·08:31 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37947?
CVE-2024-37947 is a critical Stored XSS vulnerability that impacts versions of Tutor LMS up to 2.7.2.
2
How do I fix CVE-2024-37947?
To fix CVE-2024-37947, update Tutor LMS to version 2.7.3 or later.
3
What versions of Tutor LMS are affected by CVE-2024-37947?
CVE-2024-37947 affects all versions of Tutor LMS up to and including 2.7.2.
4
What type of vulnerability is CVE-2024-37947?
CVE-2024-37947 is classified as a Cross-site Scripting (XSS) vulnerability due to improper neutralization of input.
5
Who is the vendor for CVE-2024-37947?
The vendor for CVE-2024-37947 is Themeum, the developer of Tutor LMS.