Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2976-6mfc-xmp6

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a crafted request. NOTE: this might be due to an incomplete fix for CVE-2012-5168.

user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a crafted request. NOTE: this might be due to an incomplete fix for CVE-2012-5168.

EPSS

Процентиль: 69%
0.00612
Низкий

Связанные уязвимости

nvd
больше 13 лет назад

user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a crafted request. NOTE: this might be due to an incomplete fix for CVE-2012-5168.

EPSS

Процентиль: 69%
0.00612
Низкий