Directory Traversal and Execution Flaw in ATutor by Atutor
CVE-2017-1000002
9.8CRITICAL
What is CVE-2017-1000002?
ATutor versions 2.2.1 and earlier are susceptible to a directory traversal and file extension check bypass within the Course component, allowing attackers to execute arbitrary code. Additionally, the vulnerability in the Course Icon component poses a risk of information disclosure, potentially exposing sensitive data. Ensure systems are updated to mitigate these risks.