CVE · Low

CVE-2021-24242 — Tutor LMS – eLearning and online course solution [tutor] < 1.8.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24242 Tutor LMS – eLearning and online course solution [tutor] < 1.8.8 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Low 3.8 < 1.8.8 1.8.8 2021-04-05

CVE-2021-24242

Tutor LMS prior to version 1.8.8 contains a local file inclusion flaw in the Tools section where the sub_page parameter can be manipulated by administrators and other high-privilege users to include arbitrary PHP files from the server. This vulnerability allows privileged attackers to execute code by crafting malicious requests that reference local files on the system. The issue was resolved in version 1.8.8 and later releases.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.