ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/index_inline_editor_submit.php or (2) course_category/index_inline_editor_submit.php.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/51014 | third party advisory vendor advisory |
http://osvdb.org/86428 | vdb entry |
http://www.securityfocus.com/bid/56100 | vdb entry exploit |
http://archives.neohapsis.com/archives/bugtraq/2012-10/0095.html | mailing list exploit |
http://update.atutor.ca/acontent/patch/1_2/ | patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/79461 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/79462 | vdb entry |
http://secunia.com/advisories/51034 | third party advisory vendor advisory |
https://www.htbridge.com/advisory/HTB23117 | exploit |