CVE-2023-0236
The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected products
- Tutor Lms
- Themeum Tutor Lms
- < 2.0.10
- Fix
- Available
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 1.3% (70th percentile)
- NVD status
- Modified
- Published
- 2023-02-06
CVE-2023-0236 at NVD
1 known exploit for CVE-2023-0236
Proof-of-concept code and exploit modules indexed by Sploitus