cleantalk
Vulnerabilities and Security Researches

Tutor LMS – eLearning and online course solution, CVE-2021-25017

CVE, Research URL

CVE-2021-25017

Published on
Jan 24, 2022
Research Description
The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
Affected versions
Min -, max 1.9.12.
Status
vulnerable