PT-2017-8054 · Atutor · Atutor

·

CVE-2016-2555

·

Publicado

2017-04-13

·

Atualizado

2024-02-14

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ATutor version 2.2.1
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands. This is achieved through the searchFriends function to friends.inc.php.
Recommendations For ATutor version 2.2.1, consider disabling the searchFriends function in friends.inc.php until a patch is available to prevent potential SQL injection attacks.

Exploit

Correção

RCE

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-2555

Produtos afetados

Atutor