ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email, Course Alumni, Course Enrolment, Group Membership, Course unenrolment, Course Enrolment List Search, Glossary, Social Group Member Search, Social Friend Search, Social Group Search, File Comment, Gradebook Test Title, User Group Membership, Inbox/Sent Items, Sent Messages, Links, Photo Album, Poll, Social Application, Social Profile, Test, Content Menu, Auto-Login, and Gradebook components resulting in information disclosure, database modification, or potential code execution.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-07-13T20:00:00
Updated: 2024-08-05T21:45:25.963Z
Reserved: 2017-07-10T00:00:00
Link: CVE-2017-1000004
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-07-17T13:18:16.030
Modified: 2024-11-21T03:03:56.863
Link: CVE-2017-1000004
Redhat
No data.