Beveiligingsadvies

CVE-2023-0236

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-02-06 19:59:21
Laatst bijgewerkt 2025-03-25 18:13:00
Toegewezen door WPScan
CVSS-score 6.1
Status PUBLISHED

Beschrijving

The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin