Product
atutor
53 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-27008
CVE-2021-43498
CVE-2020-23341
CVE-2020-10557
CVE-2015-1583
CVE-2014-9753
CVE-2019-16114
CVE-2019-12169
CVE-2019-12170
CVE-2019-11446
CVE-2019-7172
CVE-2015-6521
CVE-2017-14981
CVE-2015-7711
CVE-2016-10400
CVE-2017-1000004
CVE-2017-1000003
CVE-2017-1000002
CVE-2016-2555
CVE-2017-6483
CVE-2016-2539
CVE-2015-7712
CVE-2014-9752
CVE-2014-2091
CVE-2012-6528
CVE-2012-5454
CVE-2012-5453
CVE-2012-5169
CVE-2012-5168
CVE-2012-5167
CVE-2011-3706
CVE-2010-3455
CVE-2009-4945
CVE-2009-4944
CVE-2009-4942
CVE-2009-4941
CVE-2010-0971
CVE-2008-3368
CVE-2008-0828
CVE-2007-0381
CVE-2006-5734
CVE-2006-3996
CVE-2006-3821
CVE-2006-3662
CVE-2006-3484
CVE-2005-4155
CVE-2005-3404
CVE-2005-3403
CVE-2005-2956
CVE-2005-2955
CVE-2005-2954
CVE-2005-2649
CVE-2005-2044
all versions
A Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote atta
all versions
An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_
<= 2.2.4
A reflected cross site scripting (XSS) vulnerability in the /header.tmpl.php component of ATutor 2.2.4 allows attackers to execute
<= 1.4
An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged account. T
all versions
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of ad
<= 2.2
confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the
<= 2.2.4
In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which a
>= 2.2.1 and <= 2.2.4
ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP
<= 2.2.4
ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) component. This ma
<= 2.2.4
An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege.
<= 2.2.4
A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Na
all versions
Multiple cross-site scripting (XSS) vulnerabilities in ATutor LMS version 2.2.
<= 2.2.2
Cross-Site Scripting (XSS) was discovered in ATutor before 2.2.3. The vulnerability exists due to insufficient filtration of data
<= 2.2
Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject arbitrary we
<= 2.2.1
Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php. The attac
<= 2.2.1
ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Cou
<= 2.2.1
ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Application comp
<= 2.2.1
ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component
all versions
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL
<= 2.2.2
Multiple Cross-Site Scripting (XSS) issues were discovered in ATutor 2.2.2. The vulnerabilities exist due to insufficient filtrati
<= 2.2.1
Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack th
<= 2.2
Multiple eval injection vulnerabilities in mods/_standard/gradebook/edit_marks.php in ATutor 2.2 and earlier allow remote authenti
<= 2.2
Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote auth
all versions
Cross-site scripting (XSS) vulnerability in mods/_standard/forums/admin/forum_add.php in ATutor 2.1.1 allows remote authenticated
<= 2.0
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 2.1 allow remote attackers to inject arbitrary web script or
all versions
user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated
all versions
SQL injection vulnerability in user/index_inline_editor_submit.php in ATutor AContent 1.2-1 allows remote authenticated users to e
<= 1.2
Multiple cross-site scripting (XSS) vulnerabilities in file_manager/preview_top.php in ATutor AContent before 1.2-2 allow remote a
<= 1.2
ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to
<= 1.2
Multiple SQL injection vulnerabilities in ATutor AContent before 1.2-1 allow remote attackers to execute arbitrary SQL commands vi
all versions
ATutor 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installa
all versions
Cross-site scripting (XSS) vulnerability in index.php in AChecker 1.0 allows remote attackers to inject arbitrary web script or HT
all versions
AdPeeps 8.5d1 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access v
all versions
Multiple cross-site scripting (XSS) vulnerabilities in ATRC ACollab 1.2 allow remote attackers to inject arbitrary web script or H
all versions
Cross-site request forgery (CSRF) vulnerability in ACollab 1.2 allows remote attackers to hijack the authentication of arbitrary u
all versions
Cross-site scripting (XSS) vulnerability in sign_in.php in ATRC ACollab 1.2 allows remote attackers to inject arbitrary web script
all versions
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.6.4 allow remote authenticated users, with Instructor privileges,
<= 1.6.1
PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated a
<= 1.5.5
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.5.5 and earlier allow remote attackers to inject arbitrary web scr
all versions
Multiple SQL injection vulnerabilities in ATutor 1.5.3.2 allow remote attackers to execute arbitrary SQL commands via unspecified
all versions
Multiple PHP remote file inclusion vulnerabilities in ATutor 1.5.3.2 allow remote attackers to execute arbitrary PHP code via a UR
<= 1.5.3.1
SQL injection vulnerability in links/index.php in ATutor 1.5.3.1 and earlier allows remote authenticated users to execute arbitrar
all versions
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.5.3 allow remote attackers to inject arbitrary web script or HTML
all versions
SQL injection vulnerability in index.php in ATutor 1.5.3 allows remote attackers to execute arbitrary SQL commands via the fid par
all versions
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary web script o
all versions
registration.PHP in ATutor 1.5.1 pl2 allows remote attackers to execute arbitrary SQL commands via an e-mail address that ends in
all versions
Multiple PHP file inclusion vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to include arbitrary files vi
all versions
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to inject arbitrary w
all versions
ATutor 1.5.1, and possibly earlier versions, stores temporary chat logs under the web document root with insufficient access contr
all versions
config.inc.php in ATutor 1.5.1, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions
all versions
SQL injection vulnerability in password_reminder.php in ATutor before 1.5.1 pl1 allows remote attackers to execute arbitrary SQL c
all versions
Cross-site scripting (XSS) vulnerability in ATutor 1.5.1 allows remote attackers to inject arbitrary web script or HTML via (1) co
all versions
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.3 and 1.5 RC 1 allow remote attackers to inject arbitrary web sc