Atutor

Atutor

44 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.69%
  • Veröffentlicht 17.07.2017 13:18:16
  • Zuletzt bearbeitet 13.05.2026 00:24:29

ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email, Course Alumni, Course Enrolment, Group Membership, Course unenrolment, Course Enrolment List Search, Glossary...

  • EPSS 2.32%
  • Veröffentlicht 17.07.2017 13:18:16
  • Zuletzt bearbeitet 13.05.2026 00:24:29

ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Application component resulting in privilege escalation. ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control...

  • EPSS 30.83%
  • Veröffentlicht 17.07.2017 13:18:15
  • Zuletzt bearbeitet 13.05.2026 00:24:29

ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution. ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal vulnerability in ...

Exploit
  • EPSS 79.62%
  • Veröffentlicht 13.04.2017 14:59:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.

Exploit
  • EPSS 0.71%
  • Veröffentlicht 05.03.2017 20:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Multiple Cross-Site Scripting (XSS) issues were discovered in ATutor 2.2.2. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to several pages (lang_code in themes/*/admin/system_preferences/language_edit.tmpl.php)...

Exploit
  • EPSS 4.25%
  • Veröffentlicht 07.02.2017 15:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of users for requests that upload arbitrary files and execute arbitrary PHP code via vectors involving ...

Exploit
  • EPSS 2.06%
  • Veröffentlicht 16.11.2015 19:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple eval injection vulnerabilities in mods/_standard/gradebook/edit_marks.php in ATutor 2.2 and earlier allow remote authenticated users with the AT_PRIV_GRADEBOOK privilege to execute arbitrary PHP code via the (1) asc or (2) desc parameter.

  • EPSS 2.11%
  • Veröffentlicht 16.11.2015 19:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension as a customicon for a new course,...

Exploit
  • EPSS 1.22%
  • Veröffentlicht 02.03.2014 17:55:03
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Cross-site scripting (XSS) vulnerability in mods/_standard/forums/admin/forum_add.php in ATutor 2.1.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the title parameter in an add_forum action. NOTE: the origina...

Exploit
  • EPSS 1.85%
  • Veröffentlicht 31.01.2013 05:44:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 2.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) themes/default/tile_search/index.tmpl.php, (2) login.php, (3) search.php, (4) password_rem...