cleantalk
Vulnerabilities and Security Researches

Tutor LMS – eLearning and online course solution, CVE-2021-24184

CVE, Research URL

CVE-2021-24184

Published on
Apr 06, 2021
Research Description
Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to modify course information and elevate their privileges among many other actions.
Affected versions
max 1.7.7.
Status
vulnerable