cleantalk
Vulnerabilities and Security Researches

Tutor LMS – eLearning and online course solution, 53077bd4-4e30-43a9-97f0-349135242395

Published on
-
Research Description
Tutor LMS &#8211; eLearning and online course solution [tutor] < 1.9.11 Tutor LMS &lt; 2.0.9 - Reflected Cross-Site Scripting The plugin does not escape an URL before outputting it back in an attribute, leading to Reflected Cross-Site Scripting The issue was initially fixed in 1.9.13 but re-introduced in 2.0.0
Affected versions
max 1.9.11.
Status
vulnerable