nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-5438 CVE-2024-5438
MEDIUM
Tutor LMS – eLearning and online course solution <= 2.7.1 - Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Quiz Attempt Deletion
Record summary
CVE-2024-5438 has a selected CVSS score of 4.3 (medium).
Description
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.1 via the 'attempt_delete' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Instructor-level access and above, to delete arbitrary quiz attempts.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 10, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Tutor LMS – eLearning and online course solutionBrowse themeum / Tutor LMS – eLearning and online course solutionDefault status: unaffected | CVE List | Through 2.7.1 | affected |
tutor_lmsBrowse themeum / tutor_lmsDefault status: unknown | CVE List | Through 2.7.1 | affected |
References
4plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/tutor/trunk/classes/Quiz.php plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3098465 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/00ec14d4-d97b-40b1-b61b-05e911f49bb0?source=cve