cleantalk
Vulnerabilities and Security Researches

Tutor LMS – eLearning and online course solution, a9bca7a6-c409-41d4-995e-48fd0f8264a3

Published on
-
Research Description
Tutor LMS &#8211; eLearning and online course solution [tutor] < 1.9.12 Tutor LMS &lt; 1.9.12 - Subscriber+ Stored Cross-Site Scripting The plugin does not escape the &#039;Job Title&quot; field of user&#039;s profile, which could allow any authenticated users to set a Cross-Site Scripting payload in it, which will be triggered when an admin edit the related profile
Affected versions
max 1.9.12.
Status
vulnerable