vendor:
Tutor LMS
by:
Jinson Varghese Behanan
6.5
CVSS
MEDIUM
Cross-Site Request Forgery
352
CWE
Product Name: Tutor LMS
Affected Version From: 1.5.2002
Affected Version To: 1.5.2002
Patch Exists: NO
Related CWE: CVE-2020-8615
CPE: a:tutor_lms_project:tutor_lms:1.5.2
Platforms Tested: WordPress
2020
WordPress Plugin Tutor LMS 1.5.3 – Cross-Site Request Forgery (Add User)
An attacker can use CSRF to register themselves as an instructor or block other legit instructors. Consequently, if the option to create courses without admin approval is enabled on the plugin’s settings page, the attacker will be able to create courses directly as well. All WordPress websites using Tutor LMS version 1.5.2 and below are affected.
Mitigation:
Update to the latest version of the Tutor LMS plugin.