Record summary

CVE-2020-8615 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User)ExploitDB exploitby Jinson Varghese BehananNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request ForgeryCVSS 6.5

A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).

Impact

Attackers can exploit CSRF to approve themselves as instructors or block legitimate instructors, potentially disrupting the learning management system.

Remediation

update to v.1.5.3

WeaknessesCWE-352
Authorsr3Y3r53
Template tagscvecve2020wpscanpacketstormcsrfwp-pluginwptutorwordpressthemeumvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CPE: cpe:2.3:a:themeum:tutor_lms:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/tutor/
FOFA: body=/wp-content/plugins/tutor/

Source: ProjectDiscovery

References

6