
fuzzlove/ATutor-2.2.4-Language-Exploit
Releases0
Stars3
ATutor 2.2.4 Arbitrary File Upload / RCE (CVE-2019-12169)
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 8.8 HIGH | 6.8 MEDIUM | ||
ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive to the mods/_core/languages/language_import.php (aka Import New Language) or mods/_standard/patcher/index_admin.php (aka Patcher) component. | |||