CVE-2020-8615
Summary
| CVE | CVE-2020-8615 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-04 20:15:00 UTC |
| Updated | 2022-01-01 20:03:00 UTC |
| Description | A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors). |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cross-Site Request Forgery in Tutor LMS Plugin | MISC | www.jinsonvarghese.com | Third Party Advisory |
| Update Your Tutor LMS: CSRF Vulnerability Patched in Latest Version - Themeum | MISC | www.themeum.com | Release Notes, Vendor Advisory |
| Ecommerce Security: Importance, Issues & Protection Measures | MISC | www.getastra.com | Third Party Advisory |
| WordPress Tutor LMS 1.5.3 Cross Site Request Forgery ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Tutor LMS < 1.5.3 - Cross-Site Request Forgery (CSRF) Security Vulnerability | MISC | wpvulndb.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.