1
I Use This!
Activity Not Available
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2021-43498 BDSA-2020-4772 Medium Apr 08, 2022 An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTP POST para more...
2.2.4
CVE-2020-23341 BDSA-2020-4716 Medium Aug 17, 2021 A reflected cross site scripting (XSS) vulnerability in the /header.tmpl.php component of ATutor 2.2.4 allows attackers to execute arbitrary web script more...
2.2.4, 2.2.2, 2.2.1, 2.2
CVE-2019-7172 BDSA-2019-0240 Medium Jan 29, 2019 A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field to /mods/_co more...
2.2.4, 2.2.2, 2.2.1, 2.2
CVE-2019-16114 BDSA-2019-4594 High Sep 09, 2019 In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain acc more...
2.2.4, 2.2.2, 2.2.1, 2.2
CVE-2019-12170 BDSA-2019-1545 High May 17, 2019 ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component. This may result in remote co more...
2.2.4, 2.2.2, 2.2.1, 2.2
CVE-2019-12169 BDSA-2019-1696 Medium Jun 03, 2019 ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive to the mods/ more...
2.2.4, 2.2.2, 2.2.1
CVE-2019-11446 BDSA-2019-1080 Medium Apr 22, 2019 An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The Upload Files sec more...
2.2.4, 2.2.2, 2.2.1, 2.2
BDSA-2020-2086 Medium Aug 17, 2020 ATutor is vulnerable to unauthorized password resets due to how the password reset functionality generates the hash used to verify a valid reset reques more...
BDSA-2020-1186 Medium May 22, 2020 ATutor is vulnerable to SQL injection (SQLi) due to a lack of input validation of user-supplied input. This could allow an attacker with admin privileg more...