First published: Thu Apr 10 2025(Updated: )
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Themeum Tutor LMS. This issue affects Tutor LMS: from n/a through 3.4.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tutor LMS | <=3.4.0 | |
Tutor LMS | <=3.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32230 is classified as a medium-severity vulnerability due to its potential to allow cross-site scripting (XSS) attacks.
To fix CVE-2025-32230, upgrade Themeum Tutor LMS to version 3.4.1 or later.
CVE-2025-32230 affects Tutor LMS versions up to and including 3.4.0.
CVE-2025-32230 is an improper neutralization vulnerability that allows script-related HTML tags to be executed in web pages.
Yes, CVE-2025-32230 can potentially impact user data by enabling attackers to execute malicious scripts in the context of a logged-in user.