LearnPress 漏洞列表
共找到 12 个与 LearnPress 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2022-0271: LearnPress <4.1.6 - Cross-Site Scripting POC
WordPress LearnPress plugin before 4.1.6 contains a cross-site scripting vulnerability. It does not sanitize and escape the lp-dismiss-notice before outputting it back via the lp_background_single_email AJAX action. -
CVE-2022-45808: LearnPress Plugin < 4.2.0 - Unauthenticated Time-Based Blind SQLi POC
SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions. -
CVE-2022-47615: LearnPress Plugin < 4.2.0 - Local File Inclusion POC
Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions. -
CVE-2023-5558: LearnPress < 4.2.5.5 - Cross-Site Scripting POC
The LearnPress WordPress plugin before 4.2.5.5 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. -
CVE-2023-6567: LearnPress <= 4.2.5.7 - SQL Injection POC
The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the 'order_by' parameter in all versions up to, and including, 4.2.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. -
CVE-2023-6634: LearnPress < 4.2.5.8 - Remote Code Execution POC
The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making use of the call_user_func function with user input. This makes it possible for unauthenticated attackers to execute any public function with one parameter, which could result in remote code execution. -
CVE-2024-4434: LearnPress WordPress LMS Plugin <= 4.2.6.5 - SQL Injection POC
The LearnPress WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ parameter in versions up to, and including, 4.2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. -
CVE-2024-8522: LearnPress < 4.2.7.1 - SQL Injection POC
The LearnPress - WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. -
CVE-2024-8529: LearnPress < 4.2.7.1 - SQL Injection POC
The LearnPress WordPress LMS Plugin before 4.2.7.1 is vulnerable to unauthenticated SQL injection via the 'c_fields' parameter in the /wp-json/lp/v1/courses/archive-course REST API endpoint, allowing attackers to extract sensitive information from the database. -
WordPress Plugin LearnPress SQL注入漏洞(CVE-2022-45808) 无POC
WordPress Plugin LearnPress 4.1.7.3.2及之前版本存在SQL注入漏洞,攻击者可利用此漏洞获取数据库中敏感信息。 -
WordPress plugin LearnPress 跨站脚本漏洞 无POC
WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress plugin LearnPress 4.2.7版本及之前版本存在跨站脚本漏洞,该漏洞源于包含一个存储型跨站脚本漏洞。 -
WordPress Plugin LearnPress archive-course 文件包含漏洞(CVE-2022-47615) 无POC
LearnPress 是适用于 WordPress 的综合性 WordPress LMS 插件。 这是最好的 WordPress LMS 插件之一,可用于轻松创建和在线销售课程。WordPress LearnPress 插件 <= 4.1.7.3.2存在文件包含漏洞,攻击者利用该漏洞可获取敏感文件。