Sploitus

CVE-2023-0236

1 known exploit for CVE-2023-0236

The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected products
Tutor Lms
Themeum Tutor Lms
< 2.0.10
Fix
Available
CVSS 3.1
6.1 MEDIUM
EPSS
1.3% (70th percentile)
NVD status
Modified
Published
2023-02-06
CVE-2023-0236 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2023-0236

Proof-of-concept code and exploit modules indexed by Sploitus