PT-2024-3141 · Tutor Lms · Tutor Lms
Muhammad Hassham Nagori
·
Published
2024-02-22
·
Updated
2026-02-09
·
CVE-2024-1751
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tutor LMS versions up to, and including, 2.6.1
Description
The issue is related to a SQL Injection vulnerability due to insufficient protection of the SQL query structure when handling the
question id parameter. This allows a remote attacker to execute arbitrary SQL queries and gain unauthorized access to protected information. The vulnerability can be exploited by authenticated attackers with subscriber or student access, or higher, to extract sensitive information from the database. It is estimated that over 80,000 WordPress sites are potentially affected.Recommendations
For versions up to, and including, 2.6.1, update to a version that includes a fix for this issue.
As a temporary workaround, consider restricting access to the
question id parameter in the affected API endpoint until a patch is available.
Restrict access to the database to minimize the risk of exploitation.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tutor Lms