CVE-2019-12169

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
03/06/2019
Last modified:
14/02/2024

Description

ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive to the mods/_core/languages/language_import.php (aka Import New Language) or mods/_standard/patcher/index_admin.php (aka Patcher) component.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:atutor:atutor:*:*:*:*:*:*:*:* 2.2.1 (including) 2.2.4 (including)