Vulnerability index

Browse CVEs

30 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Atutor MEDIUM 6.1
CVE-2023-27008

A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to inject arb…

No fix yet
Fix from $1,600 2023-03-28
Atutor HIGH 7.5
CVE-2021-43498

An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTP POST pa…

No fix yet
Fix from $1,950 2022-04-08
Atutor MEDIUM 6.1
CVE-2020-23341

A reflected cross site scripting (XSS) vulnerability in the /header.tmpl.php component of ATutor 2.2.4 allows attackers to execute arbitrary web scri…

Fix: after 2.2.4
Fix from $1,600 2021-08-17
Acontent HIGH 8.8
CVE-2020-10557

An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged account. The upload section i…

Fix: after 1.4
Fix from $1,950 2020-03-16
Atutor HIGH 8.8
CVE-2015-1583

Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for re…

Patch available
Fix from $1,950 2020-03-02
Atutor CRITICAL 9.8
CVE-2014-9753

confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_login paramet…

Fix: after 2.2
Fix from $2,300 2020-02-11
Atutor CRITICAL 9.8
CVE-2019-16114

In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain a…

Fix: after 2.2.4
Fix from $2,300 2019-09-09
Atutor HIGH 8.8
CVE-2019-12169EPSS 73%

ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive to the mod…

Fix: after 2.2.4
Fix from $1,950 2019-06-03
Atutor HIGH 8.8
CVE-2019-12170EPSS 9%

ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component. This may result in remote …

Fix: after 2.2.4
Fix from $1,950 2019-05-17
Atutor HIGH 8.8
CVE-2019-11446EPSS 8%

An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The Upload Files s…

Fix: after 2.2.4
Fix from $1,950 2019-04-22
Atutor MEDIUM 6.1
CVE-2019-7172

A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field to /mods/_…

Fix: after 2.2.4
Fix from $1,600 2019-01-29
Atutor MEDIUM 5.4
CVE-2015-6521

Multiple cross-site scripting (XSS) vulnerabilities in ATutor LMS version 2.2.

No fix yet
Fix from $1,600 2017-10-10
Atutor MEDIUM 5.4
CVE-2017-14981

Cross-Site Scripting (XSS) was discovered in ATutor before 2.2.3. The vulnerability exists due to insufficient filtration of data (url in /mods/_stan…

Fix: after 2.2.2
Fix from $1,600 2017-10-03
Atutor MEDIUM 6.1
CVE-2015-7711

Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML vi…

Fix: after 2.2
Fix from $1,600 2017-08-31
Atutor HIGH 7.5
CVE-2016-10400

Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php. The attacker can read an arb…

Fix: after 2.2.1
Fix from $1,950 2017-07-22
Atutor CRITICAL 9.8
CVE-2017-1000003

ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Application component resulting in …

Fix: after 2.2.1
Fix from $2,300 2017-07-17
Atutor CRITICAL 9.8
CVE-2017-1000004

ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email, Course A…

Fix: after 2.2.1
Fix from $2,300 2017-07-17
Atutor CRITICAL 9.8
CVE-2017-1000002EPSS 31%

ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code e…

Fix: after 2.2.1
Fix from $2,300 2017-07-17
Atutor CRITICAL 9.8
CVE-2016-2555EPSS 80%

SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the se…

Patch available
Fix from $2,300 2017-04-13
Atutor MEDIUM 6.1
CVE-2017-6483

Multiple Cross-Site Scripting (XSS) issues were discovered in ATutor 2.2.2. The vulnerabilities exist due to insufficient filtration of user-supplied…

Fix: after 2.2.2
Fix from $1,600 2017-03-05
Atutor HIGH 8.8
CVE-2016-2539

Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of…

Fix: after 2.2.1
Fix from $1,950 2017-02-07
Atutor MEDIUM 6.5
CVE-2015-7712

Multiple eval injection vulnerabilities in mods/_standard/gradebook/edit_marks.php in ATutor 2.2 and earlier allow remote authenticated users with th…

Fix: after 2.2
Fix from $1,600 2015-11-16
Atutor MEDIUM 6.5
CVE-2014-9752

Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote authenticated users to …

Fix: after 2.2
Fix from $1,600 2015-11-16
Acontent HIGH 7.5
CVE-2012-5168

ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/index_inli…

Fix: after 1.2
Fix from $1,950 2012-10-22
Acontent MEDIUM 6.5
CVE-2012-5453

SQL injection vulnerability in user/index_inline_editor_submit.php in ATutor AContent 1.2-1 allows remote authenticated users to execute arbitrary SQ…

No fix yet
Fix from $1,600 2012-10-22
Acontent MEDIUM 6.5
CVE-2012-5454

user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arb…

No fix yet
Fix from $1,600 2012-10-22
Acontent HIGH 7.5
CVE-2012-5167

Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands via the (1) field par…

Fix: after 1.2
Fix from $1,950 2012-10-22
Atutor MEDIUM 5.0
CVE-2011-3706

ATutor 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an err…

No fix yet
Fix from $1,600 2011-09-23
Acollab HIGH 7.5
CVE-2009-4945

AdPeeps 8.5d1 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via requests to inde…

Mitigation only
Fix from $1,950 2010-07-22
Atutor MEDIUM 6.5
CVE-2008-3368

PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to ex…

Fix: after 1.6.1
Fix from $1,600 2008-07-30