What the vulnerability does
01Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeum Tutor LMS Pro tutor-pro allows Authentication Abuse.This issue affects Tutor LMS Pro: from n/a through <= 3.9.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeum Tutor LMS Pro tutor-pro allows Authentication Abuse.This issue affects Tutor LMS Pro: from n/a through <= 3.9.4.
Explanation of Vulnerability in Simple Terms
Tutor LMS Pro versions up to 3.9.4 contain an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access to the system. The vulnerability requires specific network conditions to exploit but can result in complete compromise of confidentiality, integrity, and availability. Site administrators should update to a version newer than 3.9.4 immediately.
What an attacker can do
Gain unauthorized access to the site without valid credentials and read, modify, or delete data.
Potential impact on your site
Attackers can access student records, course content, grades, and user data without logging in; they can also modify or delete site content.
Conditions required to exploit
Network access to the site; no user authentication or interaction required, but exploitation requires specific network conditions.
Key dates
External resources
Related vulnerabilities