Sploitus

CVE-2021-24242

1 known exploit for CVE-2021-24242

The Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.8 is affected by a local file inclusion vulnerability through the maliciously constructed sub_page parameter of the plugin's Tools, allowing high privilege users to include any local php file

Affected products
The Tutor Lms
Themeum Tutor Lms
< 1.8.8
Fix
Available
CVSS 2.0
5.5 MEDIUM
CVSS 3.1
3.8 LOW
EPSS
0.8% (53th percentile)
Weakness
CWE-22
NVD status
Modified
Published
2021-04-22
CVE-2021-24242 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2021-24242

Proof-of-concept code and exploit modules indexed by Sploitus