SQL Injection Vulnerability in ATutor by Responsively
CVE-2017-1000004
9.8CRITICAL
What is CVE-2017-1000004?
The ATutor Learning Management System, specifically versions 2.2.1 and prior, contains a critical SQL injection vulnerability affecting various components, including the Assignment Dropbox, Blog, Course Enrolment, and Gradebook. Successful exploitation of this vulnerability could allow remote attackers to manipulate the database, potentially resulting in unauthorized data disclosure, alteration of sensitive information, or even code execution. It is crucial for users to update to the latest version to mitigate these security risks.