CVE-2024-4352Missing Authorization in Tutor LMS

Severity
8.8HIGHNVD
EPSS
23.3%
top 4.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 16
Latest updateMay 22

Description

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'get_calendar_materials' function. The plugin is also vulnerable to SQL Injection via the ‘year’ parameter of that function due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level permissions and abo

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDthemeum/tutor_lms< 2.7.1
CVEListV5themeum/tutor_lms_pro2.7.0

🔴Vulnerability Details

2
GHSA
GHSA-482j-rhmj-w9w6: The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability ch2024-05-16
CVEList
Tutor LMS Pro <= 2.7.0 - Missing Authorization to SQL Injection2024-05-16

💬Community

12
Bugzilla
CVE-2021-47310 kernel: net: ti: fix UAF in tlan_remove_one2024-05-22
Bugzilla
CVE-2023-52835 kernel: perf/core: Bail out early if the request AUX area is out of bound2024-05-22
Bugzilla
CVE-2021-47311 kernel: net: qcom/emac: fix UAF in emac_remove2024-05-22
Bugzilla
CVE-2021-47353 kernel: udf: Fix NULL pointer dereference in udf_symlink function2024-05-22
Bugzilla
CVE-2021-47356 kernel: mISDN: fix possible use-after-free in HFC_cleanup()2024-05-22
CVE-2024-4352 — Missing Authorization in Tutor LMS | cvebase