CVE-2019-7172


01/29/2019

CVE-2019-7172

A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field to /mods/_core/users/admins/my_edit.php.

Attack vector: 
Network

Product: 
atutor: atutor

References: 
https://github.com/atutor/ATutor/issues/164

Severity: 
Medium

CVSS Score: 
4.3

CVSS Vector: 
(AV:N/AC:M/Au:N/C:N/I:P/A:N)



Don't forget to share

You may also like...

Leave a Reply

Your email address will not be published. Required fields are marked *