Description
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account via a request to mods/_core/users/admins/create.php or (2) create a user account via a request to mods/_core/users/create_user.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin GraceMedia Media Player Local File Inclusion (1.0)
WordPress Plugin InstaWP Connect-1-click WP Staging & Migration Arbitrary File Upload (0.1.0.22)
Internet Information Services Improper Authentication Vulnerability (CVE-2009-1535)
WordPress Plugin Thumbnail carousel slider Arbitrary File Upload (1.0)