Vulnerability CVE-2019-16114


Published: 2019-09-09

Description:
In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain access to the application. Next, he can change the directory that the application uploads files to, which allows him to achieve remote code execution. This occurs because install/include/header.php does not restrict certain changes (to db_host, db_login, db_password, and content_dir) within install/include/step5.php.

Type:

CWE-284

(Improper Access Control)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Atutor -> Atutor 

 References:
https://github.com/atutor/ATutor/commits/master
https://github.com/MostafaSoliman/Security-Advisories/blob/master/CVE-2019-16114/README.md

Copyright 2024, cxsecurity.com

 

Back to Top