What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Tutor LMS allows Path Traversal.This issue affects Tutor LMS: from n/a through 2.7.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Tutor LMS allows Path Traversal.This issue affects Tutor LMS: from n/a through 2.7.1.
Explanation of Vulnerability in Simple Terms
Tutor LMS versions up to 2.7.1 contain a path traversal vulnerability that allows high-privilege users to read arbitrary files from the server. An attacker with administrative or instructor access can bypass file access restrictions and retrieve sensitive files outside the intended directory. This affects confidentiality but not data integrity or availability.
What an attacker can do
Read arbitrary files from the server filesystem.
Potential impact on your site
Sensitive files on your server may be exposed to privileged users, including configuration files with database credentials.
Conditions required to exploit
Attacker must have high-level privileges (admin or instructor role) in Tutor LMS.
Key dates
External resources
Related vulnerabilities