CVE-2020-8615
WordPress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User)
Record summary
CVE-2020-8615 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User)ExploitDB exploitby Jinson Varghese BehananNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMWordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request ForgeryCVSS 6.5
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).
Impact
Attackers can exploit CSRF to approve themselves as instructors or block legitimate instructors, potentially disrupting the learning management system.
Remediation
update to v.1.5.3
Source: ProjectDiscovery