CVE-2021-25017: vulnerability in Tutor LMS – eLearning and online course solution
Tutor LMS < 1.9.12 - Reflected Cross-Site Scripting
Published · Updated
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.0%
exploitation probability
1.0%top 38% of all CVEs
observed exploitation
nono source reports it
The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
Affected products
Unknown · Tutor LMS – eLearning and online course solutionRelated CVEs — Tutor LMS – eLearning and online course solution
In the same product, most dangerous first.
CVE-2021-24182—Tutor LMS < 1.8.3 - SQL Injection via tutor_quiz_builder_get_answers_by_questionEPSS 1.7%CVE-2021-24183—Tutor LMS < 1.8.3 - SQL Injection via tutor_quiz_builder_get_question_formEPSS 1.7%CVE-2021-24184—Tutor LMS < 1.7.7 - Unprotected AJAX including Privilege EscalationEPSS 1.4%CVE-2021-24186—Tutor LMS < 1.8.3 - SQL Injection via tutor_answering_quiz_question/get_answer_by_idEPSS 1.3%CVE-2021-24185—Tutor LMS < 1.7.7 - SQL Injection via tutor_place_ratingEPSS 1.3%CVE-2021-24181—Tutor LMS < 1.7.7 - SQL Injection via tutor_mark_answer_as_correctEPSS 1.3%