CVE-2020-8615
MEDIUM NUCLEITutor LMS < 1.5.3 - Cross-Site Request Forgery
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-8615. PoCs published by Jinson Varghese Behanan. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in WordPress Plugin Tutor LMS 1.5.2 and below, allowing an attacker to add or approve an instructor account by tricking an admin into submitting a malicious request.
Description
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).
Exploits (1)
This exploit demonstrates a CSRF vulnerability in WordPress Plugin Tutor LMS 1.5.2 and below, allowing an attacker to add or approve an instructor account by tricking an admin into submitting a malicious request.
Nuclei Templates (1)
http.html:/wp-content/plugins/tutor/
body=/wp-content/plugins/tutor/
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N