CVE-2020-8615
Last modified
CVE-2020-8615 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).. EPSS estimates a 8.83% chance of exploitation in the next 30 days.
Description
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Themeum | Tutor Lms | < 1.5.3 |
References
- http://packetstormsecurity.com/files/156585/WordPress-Tutor-LMS-1.5.3-Cross-Site-Request-Forgery.htmlExploit, Third Party Advisory, VDB Entry
- https://wpvulndb.com/vulnerabilities/10058Third Party Advisory
- https://www.jinsonvarghese.com/cross-site-request-forgery-in-tutor-lms/Third Party Advisory
- https://www.themeum.com/tutor-lms-updated-v1-5-3/Release Notes, Vendor Advisory
- http://packetstormsecurity.com/files/156585/WordPress-Tutor-LMS-1.5.3-Cross-Site-Request-Forgery.htmlExploit, Third Party Advisory, VDB Entry
- https://wpvulndb.com/vulnerabilities/10058Third Party Advisory
- https://www.jinsonvarghese.com/cross-site-request-forgery-in-tutor-lms/Third Party Advisory
- https://www.themeum.com/tutor-lms-updated-v1-5-3/Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-8615?
How severe is CVE-2020-8615?
How do I fix CVE-2020-8615?
Are you affected by CVE-2020-8615?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
