ATutor records
39 published records for vendor atutor.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 3 · 7.7%
- Pre-auth RCE
- 7
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-264 Permissions, Privileges, and Access Controls2
The weakness classes this vendor ships most often: where to look.
CWEAll records
39 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
63This week | CVE-2016-2555Weaponized | SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands vatutor · atutor · CWE-89 | Critical9.8 | — | 79.6% | Apr 13, 2017 |
57Plan | CVE-2019-12169Weaponized | ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive tatutor · atutor · CWE-22 | High8.8 | — | 72.2% | Jun 3, 2019 |
48Plan | CVE-2017-1000002Weaponized | ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting atutor · atutor · CWE-22 | Critical9.8 | — | 30.8% | Jul 17, 2017 |
40Plan | CVE-2019-16114No exploit | In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him atutor · atutor · CWE-863 | Critical9.8 | — | 4.8% | Sep 9, 2019 |
40Plan | CVE-2017-1000004No exploit | ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email,atutor · atutor · CWE-89 | Critical9.8 | — | 4.7% | Jul 17, 2017 |
40Plan | CVE-2014-9753No exploit | confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_logiatutor · atutor · CWE-287 | Critical9.8 | — | 2.9% | Feb 11, 2020 |
40Plan | CVE-2017-1000003No exploit | ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Application component resuatutor · atutor · CWE-269 | Critical9.8 | — | 2.3% | Jul 17, 2017 |
38Monitor | CVE-2019-12170Proof of concept | ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component.atutor · atutor · CWE-434 | High8.8 | — | 8.6% | May 17, 2019 |
37Monitor | CVE-2019-11446Proof of concept | An issue was discovered in ATutor through 2.2.4.atutor · atutor · CWE-434 | High8.8 | — | 7.8% | Apr 22, 2019 |
36Monitor | CVE-2016-2539Proof of concept | Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentiatutor · atutor · CWE-352 | High8.8 | — | 4.3% | Feb 7, 2017 |
35Monitor | CVE-2020-10557No exploit | An issue was discovered in AContent through 1.4.atutor · acontent · CWE-434 | High8.8 | — | 1.4% | Mar 16, 2020 |
35Monitor | CVE-2015-1583No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administratoatutor · atutor · CWE-352 | High8.8 | — | 1.2% | Mar 2, 2020 |
31Monitor | CVE-2012-5167Proof of concept | Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1) atutor · acontent · CWE-89 | High7.5 | — | 4.7% | Oct 22, 2012 |
31Monitor | CVE-2012-5168No exploit | ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/iatutor · acontent · CWE-264 | High7.5 | — | 3.4% | Oct 22, 2012 |
31Monitor | CVE-2016-10400No exploit | Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php.atutor · atutor · CWE-22 | High7.5 | — | 1.9% | Jul 22, 2017 |
30Monitor | CVE-2021-43498No exploit | An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTatutor · atutor · CWE-640 | High7.5 | — | 1.6% | Apr 8, 2022 |
30Monitor | CVE-2009-4945No exploit | AdPeeps 8.5d1 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via requestatutor · acollab · CWE-255 | High7.5 | — | 1.3% | Jul 22, 2010 |
27Monitor | CVE-2012-5453Proof of concept | SQL injection vulnerability in user/index_inline_editor_submit.php in ATutor AContent 1.2-1 allows remote authenticated users to execute arbatutor · acontent · CWE-89 | Medium6.5 | — | 2.7% | Oct 22, 2012 |
27Monitor | CVE-2008-3368Proof of concept | PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administratatutor · atutor · CWE-94 | Medium6.5 | — | 2.7% | Jul 30, 2008 |
27Monitor | CVE-2014-9752No exploit | Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote authenticated atutor · atutor | Medium6.5 | — | 2.1% | Nov 16, 2015 |
27Monitor | CVE-2015-7712No exploit | Multiple eval injection vulnerabilities in mods/_standard/gradebook/edit_marks.php in ATutor 2.2 and earlier allow remote authenticated useratutor · atutor | Medium6.5 | — | 2.1% | Nov 16, 2015 |
27Monitor | CVE-2012-5454No exploit | user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to matutor · acontent · CWE-264 | Medium6.5 | — | 2.0% | Oct 22, 2012 |
24Monitor | CVE-2015-7711No exploit | Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject arbitrary web script oatutor · atutor · CWE-79 | Medium6.1 | — | 1.6% | Aug 31, 2017 |
24Monitor | CVE-2023-27008Proof of concept | A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to iatutor · atutor · CWE-79 | Medium6.1 | — | 1.5% | Mar 28, 2023 |
24Monitor | CVE-2019-7172No exploit | A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field tatutor · atutor · CWE-79 | Medium6.1 | — | 0.9% | Jan 29, 2019 |
- CVE-2016-255563This week
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands v
CriticalCVSS 9.8WeaponizedEPSS 80%atutor · atutorApr 13, 2017
- CVE-2019-1216957Plan
ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive t
HighCVSS 8.8WeaponizedEPSS 72%atutor · atutorJun 3, 2019
- CVE-2017-100000248Plan
ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting
CriticalCVSS 9.8WeaponizedEPSS 31%atutor · atutorJul 17, 2017
- CVE-2019-1611440Plan
In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him
CriticalCVSS 9.8No exploitEPSS 5%atutor · atutorSep 9, 2019
- CVE-2017-100000440Plan
ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email,
CriticalCVSS 9.8No exploitEPSS 5%atutor · atutorJul 17, 2017
- CVE-2014-975340Plan
confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_logi
CriticalCVSS 9.8No exploitEPSS 3%atutor · atutorFeb 11, 2020
- CVE-2017-100000340Plan
ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Application component resu
CriticalCVSS 9.8No exploitEPSS 2%atutor · atutorJul 17, 2017
- CVE-2019-1217038Monitor
ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component.
HighCVSS 8.8Proof of conceptEPSS 9%atutor · atutorMay 17, 2019
- CVE-2019-1144637Monitor
An issue was discovered in ATutor through 2.2.4.
HighCVSS 8.8Proof of conceptEPSS 8%atutor · atutorApr 22, 2019
- CVE-2016-253936Monitor
Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authenti
HighCVSS 8.8Proof of conceptEPSS 4%atutor · atutorFeb 7, 2017
- CVE-2020-1055735Monitor
An issue was discovered in AContent through 1.4.
HighCVSS 8.8No exploitEPSS 1%atutor · acontentMar 16, 2020
- CVE-2015-158335Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrato
HighCVSS 8.8No exploitEPSS 1%atutor · atutorMar 2, 2020
- CVE-2012-516731Monitor
Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1)
HighCVSS 7.5Proof of conceptEPSS 5%atutor · acontentOct 22, 2012
- CVE-2012-516831Monitor
ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/i
HighCVSS 7.5No exploitEPSS 3%atutor · acontentOct 22, 2012
- CVE-2016-1040031Monitor
Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php.
HighCVSS 7.5No exploitEPSS 2%atutor · atutorJul 22, 2017
- CVE-2021-4349830Monitor
An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTT
HighCVSS 7.5No exploitEPSS 2%atutor · atutorApr 8, 2022
- CVE-2009-494530Monitor
AdPeeps 8.5d1 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via request
HighCVSS 7.5No exploitEPSS 1%atutor · acollabJul 22, 2010
- CVE-2012-545327Monitor
SQL injection vulnerability in user/index_inline_editor_submit.php in ATutor AContent 1.2-1 allows remote authenticated users to execute arb
MediumCVSS 6.5Proof of conceptEPSS 3%atutor · acontentOct 22, 2012
- CVE-2008-336827Monitor
PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrat
MediumCVSS 6.5Proof of conceptEPSS 3%atutor · atutorJul 30, 2008
- CVE-2014-975227Monitor
Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote authenticated
MediumCVSS 6.5No exploitEPSS 2%atutor · atutorNov 16, 2015
- CVE-2015-771227Monitor
Multiple eval injection vulnerabilities in mods/_standard/gradebook/edit_marks.php in ATutor 2.2 and earlier allow remote authenticated user
MediumCVSS 6.5No exploitEPSS 2%atutor · atutorNov 16, 2015
- CVE-2012-545427Monitor
user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to m
MediumCVSS 6.5No exploitEPSS 2%atutor · acontentOct 22, 2012
- CVE-2015-771124Monitor
Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject arbitrary web script o
MediumCVSS 6.1No exploitEPSS 2%atutor · atutorAug 31, 2017
- CVE-2023-2700824Monitor
A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to i
MediumCVSS 6.1Proof of conceptEPSS 1%atutor · atutorMar 28, 2023
- CVE-2019-717224Monitor
A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field t
MediumCVSS 6.1No exploitEPSS 1%atutor · atutorJan 29, 2019