mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-31 05:59:31 +02:00
965 B
965 B
CVE-2021-24186
Description
The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.
POC
Reference
- https://wpscan.com/vulnerability/5f5c0c6c-6f76-4366-b590-0aab557f8c60
- https://wpscan.com/vulnerability/5f5c0c6c-6f76-4366-b590-0aab557f8c60