PT-2019-14518 · Atutorspaces · Atutor

Publicado

2019-09-09

·

Atualizado

2020-08-24

·

CVE-2019-16114

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ATutor version 2.2.4
Description The issue allows an unauthenticated attacker to modify application settings, forcing the application to use a crafted database. This enables the attacker to gain access to the application. Furthermore, the attacker can change the directory where files are uploaded, leading to remote code execution. This is due to a lack of restrictions on certain changes in the install/include/header.php file, specifically for db host, db login, db password, and content dir within install/include/step5.php.
Recommendations For ATutor version 2.2.4, restrict changes to db host, db login, db password, and content dir within install/include/step5.php to prevent unauthorized modifications. Additionally, consider implementing proper access controls to prevent unauthenticated attackers from modifying application settings.

Exploit

Correção

RCE

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-16114

Produtos afetados

Atutor