Sploitus

CVE-2021-24184

1 known exploit for CVE-2021-24184

Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to modify course information and elevate their privileges among many other actions.

Affected products
Tutor Lms
Themeum Tutor Lms
< 1.7.7
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
1.4% (71th percentile)
Weakness
CWE-862
NVD status
Modified
Published
2021-04-05
CVE-2021-24184 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2021-24184

Proof-of-concept code and exploit modules indexed by Sploitus