Password and Category Name Modification in ATutor AContent
CVE-2012-5168

Currently unrated

Key Information:

Vendor

Atutor

Status
Vendor
CVE Published:
22 October 2012

What is CVE-2012-5168?

ATutor AContent versions prior to 1.2-1 are susceptible to a security vulnerability that enables remote attackers to manipulate user passwords and category names. This is executed through direct requests made to specific scripts, namely user/index_inline_editor_submit.php and course_category/index_inline_editor_submit.php, allowing unauthorized modifications without proper authentication.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2012-5168 : Password and Category Name Modification in ATutor AContent