Sploitus

CVE-2021-24186

1 known exploit for CVE-2021-24186

The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.

Affected products
Tutor Lms
Themeum Tutor Lms
< 1.8.3
Fix
Available
CVSS 3.1
6.5 MEDIUM
EPSS
1.3% (67th percentile)
Weakness
CWE-89
NVD status
Modified
Published
2021-04-05
CVE-2021-24186 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2021-24186

Proof-of-concept code and exploit modules indexed by Sploitus