Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-16114

Опубликовано: 09 сент. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Средний

Описание

In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain access to the application. Next, he can change the directory that the application uploads files to, which allows him to achieve remote code execution. This occurs because install/include/header.php does not restrict certain changes (to db_host, db_login, db_password, and content_dir) within install/include/step5.php.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:atutor:atutor:*:*:*:*:*:*:*:*
Версия до 2.2.4 (включая)

EPSS

Процентиль: 95%
0.20795
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-863

Связанные уязвимости

github
больше 3 лет назад

In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain access to the application. Next, he can change the directory that the application uploads files to, which allows him to achieve remote code execution. This occurs because install/include/header.php does not restrict certain changes (to db_host, db_login, db_password, and content_dir) within install/include/step5.php.

EPSS

Процентиль: 95%
0.20795
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-863