cleantalk
Vulnerabilities and Security Researches

Tutor LMS – eLearning and online course solution, CVE-2021-24873

CVE, Research URL

CVE-2021-24873

Published on
Nov 24, 2021
Research Description
The Tutor LMS WordPress plugin before 1.9.11 does not sanitise and escape user input before outputting back in attributes in the Student Registration page, leading to a Reflected Cross-Site Scripting issue
Affected versions
Min -, max 1.9.11.
Status
vulnerable