Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Goodlayers Subscribe
Filtered by product Good Learning Management System
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-27481 1 Goodlayers 1 Good Learning Management System 2020-11-23 7.5 HIGH 9.8 CRITICAL
An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, which allows any unauthenticated user to get access to the function "gdlr_lms_cancel_booking" where POST Parameter "id" was sent straight into SQL query without sanitization.