CVE Database /
CVE-2021-24242
CVE · Low
CVE-2021-24242 — Tutor LMS – eLearning and online course solution [tutor] < 1.8.8
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24242
|
Tutor LMS – eLearning and online course solution [tutor] < 1.8.8 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Low
3.8
|
< 1.8.8
|
1.8.8 |
2021-04-05 |
—
|
CVE-2021-24242
Tutor LMS prior to version 1.8.8 contains a local file inclusion flaw in the Tools section where the sub_page parameter can be manipulated by administrators and other high-privilege users to include arbitrary PHP files from the server. This vulnerability allows privileged attackers to execute code by crafting malicious requests that reference local files on the system. The issue was resolved in version 1.8.8 and later releases.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings